A cybercriminal group called CMD Organization today took credit for a June 2026 cyber attack on Mount Royal University in Calgary, Alberta.
MRU on June 17 announced a cyber incident affected its systems, including payroll and student accommodation registration. The system disruptions are still ongoing as of time of writing.
CMD Organization today claimed responsibility for the breach on its data leak website. CMD says it stole more than 10 TB of data from MRU and is demanding a $1.9 million ransom within one week. To prove its claim, CMD posted sample images of what it says are documents stolen from MRU.
MRU has not acknowledged CMD’s claim and Comparitech cannot independently verify its authenticity. We do not know what data was compromised or if MRU did or will pay a ransom.
“On Wednesday, June 17, the University advised the community that it was experiencing technical disruptions affecting certain systems. We can now confirm that those disruptions are the result of a cyber incident,” says the school’s June 18 emergency update.
In a July 7, 2026 news release, the university said, “We regret to inform our community that our investigation has now shown that data within certain folders on the University’s ‘H drive’ was accessed and taken by an unauthorized actor. The actor then deleted our H drive data to impede our recovery.”
“The H drive is a file storage system used by individual employees and students. Our analysis indicates that this incident affected specific folders rather than the entire H drive. We will begin directly notifying employees and students whose H drive folders were compromised within the coming week,” the release said.
“The threat actor also deleted MRU’s “J drive,” which contains departmental data. There is currently no evidence that J drive data was accessed or copied before it was deleted. We are still working to recover deleted J drive data, but a full recovery may not be possible.”
Read the MRU’s full press release at the bottom of this article.
The university is offering employees two years of credit monitoring and identity theft protection services.
Who is CMD Organization?
CMD Organization is a new cybercriminal group that started listing victims on its data leak website in May 2026. It operates a ransomware-as-a-service scheme in which affiliates pay to use CMD’s malware and infrastructure to launch attacks and collect ransoms. Most ransomware groups negotiate with victims directly, but CMD is known to auction off stolen data to the highest bidder.
CMD has claimed responsibility for 32 ransomware attacks since it began. Of those, four were confirmed by the organizations it targeted. Its average ransom demand is $580,000.
The group’s other confirmed attacks hit:
- Shin FA-COM in Japan
- Goodstone Group in Australia
- Lorenskog Municipality in Norway
Lorenskog officials said attackers broke into their systems after an employee downloaded a malware-infected file from a website. The attackers spent two weeks mapping the city’s network before deploying the ransomware.
Ransomware attacks on education
Comparitech researchers have logged 35 confirmed ransomware attacks on schools, universities, and other educational institutions worldwide in 2026 to date.
These other schools recently confirmed ransomware attacks:
- Evanston Township High School District 202 (IL)
- Reynella East College (Australia)
- Kozminski University (Poland)
- Musashino University (Japan)
We’re monitoring 74 more unconfirmed attack claims made in 2026 to date.
Ransomware attacks on schools can both steal data and disrupt day-to-day operations such as taking attendance, submitting grades, phone and email communications, billing, payroll, and assignments. Schools that refuse to pay can face extended downtime, permanent data loss, and putting students and faculty at increased risk of fraud.
About Mount Royal University
MRU is a public university in Calgary, Alberta, Canada. It enrolls roughly 12,000 students per semester and employs 740 faculty.
Here is MRU’s full July 7, 2026 news release about the breach:
We recognize that the recent cyber incident has been concerning for many members of our community. We are sharing this information to provide an important update on the University’s ongoing investigation, share what we have learned to date, and outline the next steps we are taking to notify and support those affected.
On June 18, 2026, we advised our community that we were responding to a cyber incident affecting access to certain university systems and services. At that time, we said the investigation was in its early stages and that if the investigation determined information had been affected, impacted individuals would be notified as appropriate.
We regret to inform our community that our investigation has now shown that data within certain folders on the University’s “H drive” was accessed and taken by an unauthorized actor. The actor then deleted our H drive data to impede our recovery.
The H drive is a file storage system used by individual employees and students. Our analysis indicates that this incident affected specific folders rather than the entire H drive. We will begin directly notifying employees and students whose H drive folders were compromised within the coming week.
While our analysis of the exposed H drive data is ongoing, we will provide all current employees and all individuals employed within the past five years with two years of credit monitoring and identity theft protection services as a precautionary measure. Details about how to access this offer will be provided by email and physical mail within the coming week.
The threat actor also deleted MRU’s “J drive,” which contains departmental data. There is currently no evidence that J drive data was accessed or copied before it was deleted. We are still working to recover deleted J drive data, but a full recovery may not be possible.
Further analysis of the affected data and recoverability will take additional time and may be several weeks or months. Updates will be provided as they become available.
We have reported this incident to the Alberta Information and Privacy Commissioner and to law enforcement and will provide our full co-operation with their inquiries.
We have created a frequently asked questions (FAQ) resource that provides additional information about the cyber incident, the investigation and the supports available. We encourage you to review the FAQs, as they will be updated as new information becomes available.
We remain committed to providing updates as our investigation progresses and additional information becomes available.