Mount Royal University in Calgary confirmed that attackers breached its network on June 17, accessed and exfiltrated data from the H: drive, and then deleted the original files, while a separate J: drive containing departmental data was wiped without evidence of prior theft. The incident disrupted online services, internet access, and internal systems, and the university said the affected records may include current and former students, current and former employees, and other individuals.
The extortion group CMD Organization claimed responsibility, published samples of allegedly stolen data including passport scans, and demanded 30 BTC while threatening broader disclosure. Mount Royal University said it reported the breach to Alberta’s Information and Privacy Commissioner and law enforcement, brought in external cybersecurity experts, and warned that recovery could take weeks to months because deleted data complicates impact assessment; it is offering two years of credit monitoring and identity theft protection to current employees and people employed within the past five years.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Mount Royal University publicly confirmed the breach, reported it to Alberta’s Information and Privacy Commissioner and law enforcement, and engaged external cybersecurity experts. The university said it plans to notify impacted individuals and is offering two years of credit monitoring and identity theft protection to current employees and those employed within the past five years.
The extortion group CMD Organization claimed responsibility for the Mount Royal University attack, published samples of allegedly stolen data including passport scans, and demanded a 30 BTC ransom while threatening broader publication. One report said the group set a six-day deadline before releasing more data.
Mount Royal University said a cyberattack began on June 17, 2026, disrupting online services, internet access, and internal systems. Investigators found data on the H: drive was accessed, exfiltrated, and deleted, while data on the J: drive was deleted without evidence of exfiltration.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityweek.com
Open sourcecyberveille.ch
Open sourceteiss.co.uk
Open sourcecysecurity.news
Open sourcebleepingcomputer.com
Open sourceemergency.mtroyal.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.