Jul 12, 2026 · 6 min read
Mount Royal University: $1.9M Ransom, No Aid for Students
Ransomware group CMD Organization stole 10TB from the Calgary university's shared network drive on June 17, 2026, deleted the originals, and demanded 30 Bitcoin. Employees get two years of credit monitoring. Students exposed on the same drive get a policy statement.
Mount Royal University in Calgary spent three weeks investigating a ransomware attack before telling anyone what was taken. When it finally did, in a statement published July 8, 2026, the university drew a hard line: employees whose data was exposed get two years of free credit monitoring. Students whose data sat on the exact same drive get nothing.
Key Takeaways
- CMD Organization stole 10TB of data from Mount Royal University's shared "H drive" on June 17, 2026, then deleted the originals and demanded $1.9 million (30 Bitcoin).
- Mount Royal University is offering two years of credit monitoring and identity theft protection to current employees and anyone employed there in the last five years—but not to students.
- The university says student data "does not present the same risk profile" as employee data, even though CMD Organization posted passport scans as proof of the breach.
- CMD Organization has hit 32 organizations across 10 countries since surfacing in early 2026, using an auction style extortion model that lets buyers bid on stolen data.
- Mount Royal University reported the incident to the Alberta Office of the Information and Privacy Commissioner; full system recovery could take weeks to months.
What Happened at Mount Royal University?
Attackers broke into MRU's network on June 17, 2026, disrupting online services and internal systems across the Calgary campus. Once inside, they accessed the university's "H drive"—shared network storage used by both students and employees to save personal and academic files—and copied roughly 10TB of it. Then, instead of just leaving a ransom note, they deleted the originals, according to reporting from CBC News and Tech Times.
That steal then wipe sequence is what makes this breach worse than a typical smash and grab. Deleting the source files after exfiltration defeats the usual recovery plan—restoring from backup only brings back files the attackers already have a copy of, not files nobody else can read. A second location, the "J drive" holding departmental administrative records, was wiped in the same attack, though MRU says it has found no evidence that J drive content was copied before deletion.
Ten terabytes is enough storage to hold roughly 2 million standard PDF documents or several million scanned images—a scale consistent with years of accumulated student transcripts, employment records, and personal files rather than a narrow, targeted grab.
Who Is CMD Organization?
CMD Organization is a ransomware and extortion group whose infrastructure first appeared in late March 2026, with a TLS certificate for its leak site registered March 29 and public victim listings beginning in April. The group markets itself as an IT security firm while running a dark web extortion portal with an unusual twist: an auction style bidding system that lets third parties bid on stolen data alongside the ransom negotiation with the victim.
By July 7, 2026, the group had listed 32 victims across 10 countries, with healthcare and education leading the target list and the United States absorbing the largest share of attacks. Security researchers assess the group has limited operational maturity, suggesting it may be buying network access from initial access brokers rather than breaching targets itself—a common pattern for newer ransomware brands trying to build a reputation fast. MRU's $1.9 million demand, paid in 30 Bitcoin with a six day countdown, is among the group's larger publicized asks.
Why Aren't Students Getting Credit Monitoring?
Mount Royal University's public position is that student records carry less identity theft risk than employee records. In its statement, the university said "corporate data about the university is primarily what's at risk in the cyberattack" and that student information "does not present the same risk profile" as employee data, according to Tech Times.
That framing doesn't square with the evidence CMD Organization itself published. The group posted passport scans on its leak site as proof of the intrusion—and a stolen passport is a stolen passport regardless of whether the name on it belongs to a professor or a first year student. Both groups had files sitting on the same H drive, accessed by the same intrusion, at the same time.
The university's decision is also a break from how other recent education breaches have been handled. When ShinyHunters exposed roughly 454,000 student records at the University of Nottingham earlier this month, students were treated as the primary population needing protection—the opposite of MRU's approach. Compared against that precedent, MRU's decision to route protection toward employees and away from students looks less like a risk assessment and more like a liability calculation: employees have an ongoing legal relationship with the university that makes them easier to identify and easier to sue.
Why Email Users Should Care
A stolen passport scan or transcript rarely stays contained to one drive. Breach data like this typically resurfaces on criminal marketplaces and gets folded into phishing kits, where a scammer references a real course name, a real employee ID, or a real address to make a follow up email look legitimate. Students and staff who never get a breach notification tied to their name won't know to be suspicious when that email lands in their Gmail inbox months from now.
That's the practical cost of MRU's decision: credit monitoring catches financial fraud, but nothing in the university's response addresses the much larger population of people who will receive targeted phishing emails built from stolen data. Anyone connected to MRU—student or employee—should treat unexpected emails referencing university systems, financial aid, or HR processes with more suspicion for the next year, not less.
What Should Affected Students Do Now?
Students who used MRU's H drive for personal storage shouldn't wait for a formal notification letter before acting. A few concrete steps:
- Request your own credit report from Equifax or TransUnion Canada and check for accounts you didn't open—this works even without an official monitoring subscription from the university.
- Place a fraud alert or credit freeze with the credit bureaus if you stored a passport scan, SIN, or financial document on the H drive; freezes are free in most provinces and block new account fraud outright.
- Watch for phishing that references MRU specifically—course names, advisor names, or financial aid terminology are the kind of detail stolen H drive data would supply to a scam email.
- Ask MRU directly, in writing, whether your specific student file was among the accessed folders—the university has said only that "certain folders" within the H drive were affected, not all of it.
- File a complaint with the Alberta Office of the Information and Privacy Commissioner if you believe you were exposed and denied equivalent protection to employees; regulatory pressure is often what changes a university's coverage decision after the fact.
Looking Ahead
MRU says full system recovery could take weeks to months, and the Alberta OIPC review is still open. Whether the university extends credit monitoring to students later—under regulatory or public pressure—will say more about how seriously Canadian institutions take breach obligations than the initial policy did. For now, the gap between who was exposed and who was protected is the story, and it's a template other breached institutions may be tempted to copy unless this one gets pushback.