Mount Royal University in Calgary confirmed hackers broke into its network, stole data, and wiped file storage systems.
The attack happened on June 17. It took down online services, internet access, and internal systems. The university brought in external cybersecurity experts and launched an investigation.
Here’s what they found: the attackers accessed and copied data from the university’s “H drive” — a shared drive used by students and employees for file storage. Then they deleted the originals to make recovery harder. A separate drive labeled “J” was also wiped. “There’s currently no evidence that J drive data was accessed or copied before it was deleted,” the university says. Full recovery may not be possible.
The exposed data varies by person. It includes information on current and former students, employees, and others. The university says it will contact affected individuals directly once they’ve been identified.
A threat group called CMD Organization has claimed responsibility. They posted sample data online — including passport scans — and demanded 30 BTC (roughly $1.9 million). They gave the university six days to pay up before leaking everything.
CMD Organization runs an auction-style operation, offering to sell stolen data exclusively to the highest bidder. They’re currently listing 30 organizations on their extortion site.
The university is offering two years of credit monitoring and identity theft protection to all current employees and those employed in the past five years. Recovery could take weeks or months.
The incident has been reported to the Alberta Information and Privacy Commissioner and to law enforcement.
