The Calgary school says an extortion group tied to a $1.9 million ransom demand accessed personal data on a shared drive before wiping it to hinder recovery.

Mount Royal University in Calgary has confirmed that hackers who breached its network in June stole data from a shared file storage system used by students and employees, then deleted the original files in an apparent effort to block recovery efforts.
The university first notified its community of a cyberattack on June 18, 2026, following an intrusion that occurred June 17. The breach disrupted a wide range of university systems, including online services, internet access, phone lines, the university website and certain internal platforms. Mount Royal University, a public institution with more than a century of history and 11,560 students, including 12,500 undergraduates, has engaged technical teams and outside cybersecurity experts to investigate the incident and support recovery.
In a July 7 update posted to its incident webpage, the university said its investigation determined that data within certain folders on its "H drive" was accessed and removed by an unauthorized actor, who then deleted the H drive data to impede recovery. The H drive serves as a file storage system for individual students and employees, and the university said its analysis showed that specific folders, not the entire drive, were affected. The compromised folders contained information tied to current and former students, current and former employees, and an unspecified group described only as "other individuals."
Students have said the H drive was commonly used to access assignments and course readings or to store digital audio, video, image and text files, and that it may have held employees’ lesson plans, presentation materials and grading records. The university said the drive was intended to support academic work rather than serve as a personal data repository, but acknowledged it may contain personal information depending on what individuals chose to store there. It said it is notifying all individuals whose folders were compromised.
A separate drive, labeled "J" and used to store departmental data, was also wiped in the attack. The university said there is currently no evidence that J drive data was accessed or copied before deletion, and that recovery efforts are ongoing but may not fully succeed.
Because the stolen H drive data varied by individual and the original files were deleted, the university said determining the precise scope of exposure for each person will take time. It said its review of potential exposure of broader university data, including employee records, is continuing and its understanding may evolve. Affected individuals will receive personalized notifications once identified.
The university confirmed the intrusion involved a ransomware threat actor but declined to discuss the specifics of any negotiations. The attack has been claimed by a group calling itself CMD Organization, which has posted samples of allegedly stolen material, including passport scans and other sensitive documents, to its extortion site. The group demanded a ransom of 30 bitcoin, worth roughly $1.9 million, and gave the university six days to pay before threatening to publish the full set of stolen data. CMD Organization operates an auction-style extortion model in which stolen data is offered exclusively to the highest bidder, and it currently lists 30 organizations on a leak site accessible through both the clear web and the dark web.
Mount Royal University said restoring affected systems could take several weeks to months and pledged further updates as they become available. It reported the incident to the Alberta Information and Privacy Commissioner and to law enforcement. The university is offering two years of credit monitoring and identity theft protection to all current employees and anyone employed by the school within the past five years, though that coverage does not extend to students who stored personal files on the H drive.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543