
Ruhr University Bochum (RUB) recently announced that it had been hit by a ransomware attack and was forced to shut down large parts of its central IT infrastructure, including backup of. systems The attack took place on the night May 6th and 7th.
RUB is a German university with over 42,900 students and 5,800 employees. For the past two years, it has been ranked among the top 500 universities in the world.
“Due to significant technical issues with the IT infrastructure, a large number of systems were out of service from 8 a.m. on Thursday, May 7, 2020,” the university said.
“As a result, all RUB members were unable to access the Outlook mail program and the VPN tunnel, which is necessary for accessing various folders. There was also no access to the internal portal.”
RUB said its systems were affected by a cyberattack targeting the university's central IT infrastructure and leading to the shutdown of a large part of the systems.
Experts recommended shutting down all connected Windows-based server systems, as the situation had not been clarified.
“The nature of the attack is still being analyzed,” the university said in a press release hours after the attack. “All central servers and backup systems that could have been affected have been taken offline.”

Experts asked students and university employees to limit their use of Windows-based applications and not open email.
The university also said that its management systems were also down, as were email services via the Exchange system.
Other applications, such as RUB-Mail, Moodle, Rub-Cast, Zoom and Matrix (Riot) remained available and IT staff said they were not affected by the ransomware attack.
“It is considered highly unlikely that these applications by the attack. Therefore, the use of these systems is permitted, in particular for the continuation of digital teaching. Digital teaching is currently possible, without restrictions, through these systems.”
RUB's IT staff and an external team of experts are working together to analyze the attack and accurately determine the damage caused.
At this time, we do not know if the attackers stole data belonging to students, employees, or researchers. It is also not known if any of the systems were infected with malware.
RUB suspects that the attackers used Windows malware to infect the university's systems, as not Linux and macOS systems were affected by the attack.
Later, the university confirmed that it was a ransomware attack.
