Mount Royal University confirms breach as hackers claim attack

Mount Royal University Falls Victim to Cyberattack, Exposing Sensitive Data

A disturbing breach has hit Mount Royal University in Calgary, Alberta, Canada, leaving thousands of students and employees vulnerable. Hackers claiming affiliation with the threat group CMD Organization have accessed a university network, stolen sensitive data, and even deleted some files to hinder recovery efforts.

The cyberattack, which occurred on June 17, disrupted various university systems, including online services, internet access, and internal systems. The affected individuals include current and former students, employees, and an unspecified category of “other individuals.” According to the university’s investigation, hackers accessed certain folders on the H drive, where sensitive information is stored.

The hackers’ tactics were particularly cunning: after stealing data from the H drive, they wiped a separate drive labeled “J,” which contained departmental data. Unfortunately, there is currently no evidence that any J drive data was copied before it was deleted, making recovery efforts even more complicated. The university has reported this incident to both law enforcement authorities and the Alberta Information and Privacy Commissioner.

The CMD Organization, which claimed responsibility for the attack, has published samples of allegedly stolen data online, including passport scans and other sensitive documents. The threat group has also demanded a 30 BTC ransom (approximately $1.9 million) in exchange for not releasing all the stolen information. This auction-style extortion is a disturbing trend, with CMD Organization listing 30 organizations on its extortion site.

In response to this breach, Mount Royal University is offering two years of credit monitoring and identity theft protection to affected individuals. The university has also stated that it will provide updates as new details become available regarding the recovery efforts, which are expected to take several weeks or months.

This incident serves as a stark reminder for organizations and individuals alike: no matter how robust your security measures may be, there is always room for improvement. In this case, hackers exploited vulnerabilities in the university’s network to gain access to sensitive data. The takeaway here is that security teams must continually test their systems and protocols to stay ahead of potential threats.

As we navigate an increasingly complex cybersecurity landscape, it’s essential to remember that no organization is immune to cyberattacks. By staying vigilant, investing in robust security measures, and regularly testing our defenses, we can reduce the likelihood of falling victim to such incidents.


Source: Bleeping Computer — 2026-07-08