Mount Royal University has confirmed it suffered a data breach following a cyber incident that disrupted multiple university services in June. The cyber attack, which occurred on June 18, has now been identified as a “targeted attack” in which an unauthorized attacker accessed , stole and deleted data stored on the university’s internal systems.

As the investigation continues, the institution is taking steps to notify affected individuals, enhance its response, and provide identity protection services to employees.
Cyberattack at Mount Royal University Leads to Data Theft and Deletion
Mount Royal University (MRU) in Calgary announced that the cyber incident was more than just a service interruption. According to the university, an unauthorized attacker gained access to specific folders within the institution's H drive, a file storage system used by staff and students.
Researchers determined that the attacker not only accessed and stole data from these folders, but also deleted the contents, in an apparent attempt to thwart recovery efforts. The university emphasized that only specific folders on the H drive were affected, not the entire storage system.
See also: University of Sydney: Student and staff data breach

Some Employees and Students Were Affected
The data breach affected records belonging to both students and staff, although the full scope of the compromised information remains under investigation.
The university said only specific files were compromised, but it will begin notifying affected individuals within the week.
See also: Princeton University reveals data breach
As a precautionary measure, it will services identity theft protection, for two years, to all current employees, as well as anyone who has worked at the university in the past five years. Instructions for accessing these services will be distributed via email and physical mail.

Department Files Were Also Affected
In addition to breaching the H drive, the perpetrator also deleted the university's J drive , which stores departmental files.
While researchers confirmed that the J drive was deleted, they said there is currently no evidence that its contents were compromised or copied before being deleted. Recovery efforts are ongoing, however, the university acknowledged that recovering all of the deleted data may not be possible.
See also: University of Nottingham: Data breach affects 450,000 people
The investigation is expected to continue for weeks or months
Mount Royal University said its investigation into the incident remains active and could take weeks or even months. Digital forensics experts are continuing to examine the compromised systems to determine the full scope of the data breach and identify exactly what information was accessed.
The university said it will continue to provide updates as new information becomes available. Officials are also working to restore the affected systems, although recovery efforts remain ongoing due to the deletion of critical files.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
