A Calgary University Hit with Cyberattack, Hackers Demand $1.9 Million Ransom
Mount Royal University in Calgary has confirmed a breach of its network after hackers stole and then deleted data from its file storage systems. The attack, which occurred on June 17, disrupted various university systems, including online services and internal systems.
The university has engaged technical teams and external cybersecurity experts to investigate the incident and support recovery efforts. So far, it’s clear that the attackers targeted a drive used by students and employees for file storage, stealing data stored in certain folders labeled as “H.” These folders contain information affecting current and former students, current and former employees of the university, and an unspecified category of individuals.
The hackers also wiped a separate drive, labeled “J,” which stored departmental data. While there’s no evidence that this data was accessed or copied before it was deleted, recovering the lost information may not be possible. The university has reported the incident to both law enforcement authorities and the Alberta Information and Privacy Commissioner.
The threat group behind the attack, known as CMD Organization, claims to have published samples of the stolen data online, including passport scans and other sensitive documents. They’ve demanded a 30 Bitcoin ransom – approximately $1.9 million – with a six-day deadline for response before leaking the full set of stolen information. The attackers seem to operate an auction-style system, offering exclusive sales to the highest bidder.
CMD Organization lists 30 organizations on its extortion site and operates both clear web and dark web portals. Mount Royal University has warned that affected individuals will be contacted directly via personalized notifications once they’re identified, but the university acknowledges that determining the exact impact for each individual is complicated due to the deleted data.
Recovery efforts may take several weeks or even months, with the university providing updates as new details become available. To support those potentially impacted by the breach, Mount Royal University is offering two years of credit monitoring and identity theft protection to all current employees and individuals employed in the past five years.
This incident serves as a stark reminder that even robust security measures can be breached. It’s essential for organizations and individuals alike to remain vigilant and proactive in their cybersecurity efforts, including regularly testing systems and processes to prevent similar attacks from slipping through undetected.
Source: Bleeping Computer — 2026-07-08