Yaamlabs

Ransomware

Osaka university ransomware stops 500 servers and backups

Osaka Metropolitan University cancelled a week of classes after ransomware hit its virtualization platform and backups. What is confirmed, and what to change.

In the early hours of Friday, October 2, Osaka Metropolitan University (OMU) lost most of its information infrastructure. The university learned of the failure from the company it outsources system operations to, cancelled that day's classes across all five campuses, and then extended the cancellation to October 8. At a press conference on Monday, October 5, it said it believes the cause was a ransomware attack. Japanese media, citing university officials, reported that about 500 servers stopped at once, that the attackers got into the virtualization platform the university's systems share, and that much of the backup data needed for recovery was encrypted too.

OMU was formed in 2022 from the merger of Osaka City University and Osaka Prefecture University, and the affected systems hold records on at least 130,000 current and former students, graduates and staff. The university says it has not confirmed that any personal data was stolen and is still investigating. No ransomware group has claimed the attack, and OMU has not said whether it received a ransom demand. In-person classes resumed on October 9. For any university or school that runs its services on one shared virtualization cluster, the details that came out of the press conference are the useful part.

What is confirmed and what is not

The university's own written notices, posted on a temporary site, describe "a large-scale failure of the information infrastructure system" and say the cause is under investigation. The ransomware finding comes from the October 5 press conference, as reported by Kyodo, MBS, the Yomiuri Shimbun, Jiji Press, Business+IT and The Record. The university has published no forensic findings.

Two reports, from MBS and Business+IT, say the attackers entered the virtualization platform used by the university's information systems, and that about 500 related servers stopped together. MBS, Business+IT and the Yomiuri report that many of the backups were encrypted as well. Kyodo and Business+IT add that the university found traces of some data having been altered. OMU has not named its hypervisor product, the way in, or how the attackers reached the backups. This post does not guess at any of those.

Reported unavailable: the campus network, university email, the portal, the learning and assignment systems, academic administration, financial accounting, payroll, human resources, library services and the public website. The medical school hospital kept treating patients because its electronic medical record system is managed separately, and the veterinary clinical center also kept running, though both websites went down. The online application and enrollment sites for admissions run on external servers and stayed up, and the university extended deadlines that fell on October 8 or 9 to October 22.

The stored personal data covers former Osaka City University students since 1995 and former Osaka Prefecture University students since 2005. Kyodo and Business+IT list names, addresses, email addresses, phone numbers and student ID photos. The university reported the incident to the Osaka Prefectural Police, the Ministry of Education, Culture, Sports, Science and Technology and the Personal Information Protection Commission.

How one platform took down a whole university

A virtualization platform runs many servers as virtual machines (VMs) on a small number of physical hosts, managed from one console. The portal, email, the learning system and payroll can all share the same hosts and storage, so anyone who controls the hypervisor layer can stop or encrypt every VM on it at once, by encrypting the virtual disk files on the shared datastore. Endpoint protection running inside each VM never sees this, because the encryption happens underneath it.

Backups fail in the same event when they share that layer. If the backup server is itself a VM on the cluster, if the backup repository is a share the hypervisor admin account can write to, or if backup console logins sit in the same Active Directory domain the attacker already controls, the backups are just more files to encrypt.

Ransomware crews have worked this way for years. In July 2024 Microsoft reported several groups abusing CVE-2024-37085 in VMware ESXi, where a domain-joined host gives full admin rights to any domain group named "ESX Admins". Attackers with domain rights created the group, then encrypted the host's datastore. Broadcom fixed it in ESXi 8.0 Update 3.

What to do

These steps suit universities, colleges and school districts, but any organisation that runs most services on one cluster can use them.

  1. Take the hypervisor out of the main domain. Manage vCenter, ESXi or Hyper-V hosts with accounts that are not in the campus Active Directory, or from a separate admin forest, with phishing-resistant MFA on the management console. On ESXi, enable lockdown mode, set VMkernel.Boot.execInstalledOnly to true so unsigned binaries cannot run, and turn off SSH and the ESXi Shell unless a change ticket needs them.
  2. Put management interfaces on their own network. Hypervisor consoles, host management ports, storage networks and backup servers belong in a management VLAN reachable only from named jump hosts, with nothing from the student or staff networks allowed in.
  3. Break the backups out of the blast radius. Keep at least one copy immutable or offline, on storage the hypervisor admins cannot delete, with credentials stored nowhere on the domain. Then restore a real system, such as the learning platform, onto clean hardware and time it.
  4. Treat the outsourced operator as part of your identity perimeter. OMU heard about its outage from its operations contractor. Review which contractor accounts hold admin rights on hosts and backups, require MFA on their remote access, and log their sessions.
  5. Keep teaching and admissions running on separate infrastructure. OMU's admissions sites stayed up because they were hosted externally. Decide which services must survive a full campus outage (admissions, payment of fees, course materials, exam schedules) and host them, or a fallback for them, somewhere that shares no credentials with the campus.
  6. Prepare incident communications before you need them. With its website and email down, OMU posted notices on a temporary site that does not share infrastructure with the campus, and pointed students and applicants to its separately hosted entrance page. Register the backup domain in advance, write template notices for students, staff and applicants, decide how you reach students whose only address is on the university mail server, and agree who approves each message.

To check whether your platform has already been touched, look in your domain controllers' Security log for the creation of an "ESX Admins" group or any change to the group your hosts trust for admin rights (event IDs 4727, 4728, 4737). On ESXi hosts, review /var/log/auth.log and /var/log/shell.log for SSH logins and commands you did not run, and the vCenter events list for new local accounts or permission changes. In the backup console, check for deleted restore points, shortened retention or disabled immutability.

If you are hit, rotate the hypervisor root and vCenter administrator passwords, the backup service accounts and the contractor's remote access credentials once you have rebuilt from clean media. A university that holds data on 130,000 people should also expect to notify its regulator, as OMU did, before it knows whether data left the network.

The wider lesson for universities

Hundreds of servers on one virtualization platform is normal in higher education now, and OMU's hospital records kept working because they ran separately. Ask which of your services share the hypervisor console and backup credentials, and which must still run on day two of an outage.

Our network penetration testing can start from a student or staff network and show whether an attacker could reach your hypervisor and backup consoles, and our safeguarding and hardening work moves hypervisor, backup and contractor access onto separate accounts and networks. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.


Sources: The Record, Osaka Metropolitan University temporary notice site, OMU second report, OMU fourth report, Kyodo via Kahoku Shimpo, Kyodo via Kumamoto Nichinichi, Jiji Press via Nippon.com, Yomiuri via News On Japan, Yomiuri via Yahoo! News Japan, MBS News, Business+IT, ITmedia NEWS, innovaTopia, Microsoft Security blog on CVE-2024-37085, Help Net Security.

Back to the blog, or read this post on the full site.