Calgary university loses student and staff files to hackers who wiped the originals

Mount Royal University says a June 17 break-in ended with stolen data on shared drives and a ransom demand of 30 bitcoin from a group calling itself CMD Organization.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
A quiet university server room at night, rows of dark storage racks with faint blue and amber status lights, one rack door left ajar, cables hanging loose, a re
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Mount Royal University in Calgary confirmed hackers broke into its network on June 17, 2026 and stole files from students and staff.
  • Attackers copied data from the university's shared H drive, then deleted the originals to make recovery harder.
  • A group calling itself CMD Organization has claimed the attack and is demanding 30 bitcoin, roughly 1.9 million US dollars.
  • The university has notified the Alberta Information and Privacy Commissioner and police, and is offering two years of credit monitoring to current and recent employees.
  • Full recovery of the wiped systems could take weeks to months, and some data may be gone permanently.

Mount Royal University, a public institution in Calgary with 11,560 students, has confirmed what staff and students suspected since June: hackers got in, took files, then trashed the originals on the way out.

The break-in happened on June 17. It knocked out online services, campus internet and several internal systems. The university has been drip-feeding updates ever since, and the latest is the worst yet.

What did the hackers actually take?

They targeted the university's "H drive," the shared network storage that students and employees use for documents. Think of it as a large communal filing cabinet, just hosted on the university's servers rather than a physical room.

Certain folders on that drive were, in MRU's words, "accessed and taken by an unauthorized actor." The affected records belong to people in three groups: current and former students, current and former staff, and a third category the university describes only as "other individuals."

A second shared drive, the "J drive" used for departmental files, was wiped entirely. MRU says there's no evidence that data was copied before deletion. Recovery is ongoing, but a full restore may not be possible.

The breach has been reported to the Alberta Information and Privacy Commissioner and to law enforcement.

Who is behind it?

CMD Organization claimed the attack, first reported by BleepingComputer. The group has posted samples of what it says is stolen material, including passport scans.

It's demanding 30 bitcoin, worth roughly 1.9 million US dollars at the time of writing, and gave MRU six days to pay before publishing the full haul. The group runs extortion sites on both the open web and the dark web (a part of the internet that requires specialist software to reach) and currently lists 30 victim organisations.

Unusually, CMD Organization runs an auction model: stolen data goes to the highest bidder rather than being dumped publicly. That's a nastier variant of the standard playbook. A private buyer can do whatever they want with the files, and victims have no way to know where the data ends up.

Higher education has become a reliable target. Our July 6 story "When the Learning Platform Goes Dark, There Is No Backup Plan" noted that universities have paid ransoms twice and that the pattern is now baked into threat actors' targeting decisions.

Should you worry?

If you're a current or former MRU student or staff member, yes, a little. Because the originals were deleted, working out exactly what each person lost will take time, and MRU says it'll contact affected individuals directly once it knows who they are.

Current employees and anyone who worked at the university in the past five years are being offered two years of free credit monitoring and identity theft protection. Take it. If a passport scan or student record was in those folders, watch for suspicious emails referencing your time at MRU, and treat any call claiming to be from the university's IT or finance teams with scepticism.

Recovery will take weeks to months. For a century-old institution running on shared drives like every other university, this is going to be a long summer.

© 2026 Threat Vectr