← All news

breach

Mount Royal University Breach: H Drive Stolen, J Drive Wiped

2026-07-09

Mount Royal University in Calgary has confirmed that attackers who broke into its network on 17 June copied files from a shared storage drive and then deleted the originals on their way out. A group calling itself CMD Organization has claimed the attack and is demanding 30 BTC, roughly $1.9 million, with a six-day countdown before it publishes everything.

The stolen files came from MRU's H drive, the shared space students and staff use for everyday storage. Affected people include current and former students, current and former employees, and a category the university is vaguely calling "other individuals". A second drive, the J drive used for departmental data, was also wiped. There's no clear evidence it was copied first, though full recovery isn't guaranteed either way.

Passports already in the sample

Samples the attackers have posted publicly already contain passport scans and other sensitive documents. CMD Organization runs an auction-style leak site on both the clear and dark web, currently listing around 30 victims and hawking stolen data to the highest bidder. MRU is now one of them.

The university has notified the Alberta Information and Privacy Commissioner and law enforcement, and is offering two years of credit monitoring to current employees and anyone who worked there in the past five years. Students, past and present, aren't part of that offer.

The wipe-on-exit problem

The detail worth sitting with is the deletion. Attackers who steal data and leave the originals behind create a mess. Attackers who steal data and then delete the originals create a much harder mess, because the victim can no longer look at the source files to work out exactly who was in them.

MRU has been upfront about this. Identifying who was affected will take time, because the reference material is gone. Anyone who ever saved something personal to a university shared drive is now waiting to hear whether it was in the haul.

  • Breach date: 17 June
  • Ransom demand: 30 BTC (about $1.9 million)
  • Deadline: six days before public release
  • Drives affected: H (shared user storage), J (departmental), wiped
  • Credit monitoring: two years, current employees and anyone employed in the last five years

A long road back

Recovery is expected to run for weeks or months. For an institution of 11,560 students with more than a century of records behind it, rebuilding shared drives from backups and institutional memory is not a quick job. Departments that relied on the J drive for working files are already discovering which of their processes were quietly dependent on it.

The other question sitting in the background is how the attackers reached shared file storage in the first place, and how they had enough persistence and access to both copy and delete at scale before anyone noticed. MRU hasn't shared details on the initial access, and probably won't until the investigation wraps.

For now, the tangible parts are the leaked passport scans, the six-day clock, and a very long list of people wondering whether their files were on the drive when it walked out the door.

Mount Royal University Breach: H Drive Stolen, J Drive Wiped | RiskSense