# Mount Royal University Confirms Major Breach After Attackers Wipe Storage Drives and Demand $1.9M Ransom


A significant ransomware attack against Mount Royal University (MRU) in Calgary has exposed sensitive personal data from tens of thousands of current and former students and employees, while attackers destroyed critical departmental files in what security researchers describe as an increasingly common destruction tactic. The threat group CMD Organization claimed responsibility for the June 17 breach, demanding approximately $1.9 million in Bitcoin (30 BTC) within six days or face public data disclosure.


The university's formal incident disclosure reveals a layered attack: threat actors not only extracted sensitive documents but deliberately wiped storage systems to maximize disruption and complicate recovery efforts—a pattern emerging across higher education institutions facing ransomware campaigns.


## The Threat


Mount Royal University issued a public statement confirming that attackers successfully infiltrated university network infrastructure and accessed the institution's shared "H drive," a centralized file storage system used by thousands of students, faculty, and staff. The breach compromised personal information stored across "certain folders," including:


  • Passport scans and travel documents
  • Personal identification documents
  • Employment and enrollment records
  • Financial and sensitive administrative data

  • In a secondary destruction phase, attackers also wiped a separate storage volume labeled the "J drive," which contained departmental data and operational files. University officials stated that while there is currently no evidence the J drive data was accessed before deletion, full recovery of the deleted files may not be possible, complicating both forensic investigation and impact assessment.


    CMD Organization, the extortion group behind the attack, published sample files to the public internet as proof of compromise and issued a six-day deadline before threatening to auction stolen data to third parties through its ransom portal. The group operates both clear-web and dark-web marketplaces and currently lists approximately 30 victim organizations.


    ## Background and Context


    Mount Royal University is a 100-year-old public institution serving over 11,500 students across multiple campuses in Calgary, Alberta. The university operates extensive online learning platforms, research networks, and administrative systems connecting thousands of faculty, staff, and external stakeholders—making it an attractive target for organized ransomware operations seeking to maximize ransom leverage.


    The June 17 incident disrupted critical university services, including:

  • Online learning and course management systems
  • Internet access across multiple campus facilities
  • Internal administrative and financial systems
  • Email and communication infrastructure

  • CMD Organization is a relatively newer threat actor in the ransomware landscape, operating through a sophisticated extortion-as-a-service (EaaS) model. Unlike traditional single-victim ransomware gangs, CMD uses an auction system to sell compromised data to the highest bidder, monetizing stolen information even when victims refuse to pay. This model has proven effective at generating revenue while maintaining the threat of reputational damage.


    ### Timeline of Events


    | Date | Event |

    |------|-------|

    | June 17, 2026 | Cyberattack detected; H drive breached, J drive wiped |

    | June 17–present | Investigation and system recovery underway |

    | July 8, 2026 | Public confirmation of breach and data exposure |

    | TBD | Personal notification phase begins |

    | Recovery estimate | Several weeks to several months |


    ## Technical Details


    The attack methodology reflects sophisticated operational security awareness. Rather than simply exfiltrating data and departing, attackers employed a dual-impact strategy:


    ### Data Exfiltration

    The H drive breach accessed personal information from a broad population spanning:

  • Current and former students (exact number not disclosed)
  • Current and former employees (previous five years likely included)
  • "Other individuals" (category remains unspecified—possibly contractors, vendors, or associates)

  • The university has not disclosed the complete data inventory, stating that determining "exact impact for each individual" will require time due to the partial data destruction and complex folder permissions.


    ### Data Destruction

    The J drive wipe appears designed to accomplish multiple objectives simultaneously:

  • Operational disruption: Eliminate departmental workflows and project data
  • Recovery prevention: Destroy backup or redundant copies if stored on the same logical volume
  • Forensic complication: Limit investigation into attacker movements and persistence mechanisms

  • The fact that attackers successfully deleted files on a departmental drive suggests they either obtained elevated access credentials or exploited unpatched privilege escalation vulnerabilities—indicating potential persistence beyond the initial breach date.


    ## Implications for Educational Institutions


    This incident reflects a critical vulnerability across the higher education sector:


    Shared Storage Risk Model: Universities routinely implement centralized shared drives (H drives, network folders) to enable collaboration, but these systems often receive security scrutiny lower than perimeter defenses or public-facing applications. Once inside the network, attackers encounter minimal segmentation protecting these repositories.


    Ransomware Economics: At $1.9 million, the CMD Organization ransom demand is calibrated to be within the financial reach of medium-sized institutions—high enough to justify payment as "insurance" or a contained loss, yet low enough that university leadership may consider it preferable to prolonged operational disruption and potential liability from compromised student records.


    Dual Destruction Pattern: The deliberate file-wiping component suggests ransomware operators are evolving beyond pure encryption-based models. Destruction-as-leverage is particularly damaging in academic environments, where departmental research data, thesis repositories, and institutional records often lack adequate off-site backups.


    Privacy Breach Cascades: Educational data breaches create downstream liability. Universities are now obligated to notify the Alberta Information and Privacy Commissioner and all affected individuals, triggering:

  • Credit monitoring obligations (MRU offering two years of complimentary service)
  • Potential regulatory investigations
  • Reputational damage affecting enrollment and donor confidence
  • Litigation from compromised individuals

  • ## Recommendations for Universities and Educational Institutions


    ### Immediate Actions

  • Conduct forensic analysis of access logs to determine initial compromise vector and dwell time
  • Segment network architecture to isolate shared storage from general network segments
  • Audit user permissions on all shared drives and enforce least-privilege access principles
  • Implement offsite, immutable backups with air-gapped storage for critical departmental data

  • ### Medium-Term Hardening

  • Deploy endpoint detection and response (EDR) across administrative and research systems
  • Implement multi-factor authentication for all file share access, especially administrative accounts
  • Enable detailed file access logging to detect unusual bulk data exfiltration
  • Establish incident response playbooks specifically for ransomware targeting shared storage
  • Conduct security awareness training focused on credential theft and phishing targeting administrative staff

  • ### Organizational Preparedness

  • Establish ransomware response protocols that include law enforcement notification and legal consultation before any ransom payment
  • Maintain cyber insurance with coverage for both ransomware payments and notification/credit monitoring obligations
  • Create data inventory documentation to enable rapid assessment of breach impact
  • Develop communication templates for notifying affected individuals and maintaining transparency

  • ---


    ## HackWire Analysis


    The Mount Royal University incident represents a troubling evolution in ransomware targeting educational institutions. What distinguishes this attack is not the data exfiltration—universities have experienced plenty of those—but the deliberate destruction of the J drive data, which signals attackers are now optimizing for institutional chaos rather than just financial extortion.


    This matters now because universities are experiencing coordinated campaigns from professional ransomware groups who have profiled the sector: limited IT budgets, distributed network architecture, high tolerance for downtime (which disrupts students), and compliance obligations that incentivize rapid payment or settlement. The $1.9M ask is precisely calibrated to fit within institutional risk tolerance.


    The hidden risk others are missing: most universities assume they can recover from ransomware if they refuse to pay. This incident shows that assumption is broken. When attackers destroy departmental data *in addition to* encrypting or exfiltrating it, institutions lose leverage. You can't restore what was deleted, and cyber insurance often excludes payment for data destruction separate from encryption-based ransom.


    The concrete next step for university IT teams is immediate: audit your shared storage architecture and determine whether your offsite backups are truly immutable and air-gapped. If your backup system is still connected to your production network or uses the same credentials as daily operations, you are one ransomware breach away from losing both the original files and the copies.


    For law enforcement and provincial regulators: the pattern of CMD Organization operating an auction system for stolen data, combined with claims against 30+ organizations simultaneously, suggests this is a professional operation. Focusing recovery efforts on the extortion sites and cryptocurrency transaction tracking may yield investigative returns faster than individual victim negotiation.


    HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)