Ransomware Mount Royal University hit by ransomware attack, data stolen and deleted July 9, 2026 Share By SC Staff (Adobe Stock) Mount Royal University in Calgary has confirmed that hackers stole and subsequently deleted data from its file storage systems after breaching the university's network on June 17. The incident disrupted a wide range of university systems, including online services and internet access, according to a recent report by Bleeping Computer. The cyberattack, claimed by the threat group CMD Organization, involved the theft of data from the university's "H drive," which contained information for current and former students and employees. The attackers also deleted data from a separate "J drive" used for departmental files, though there is no evidence it was accessed before deletion. CMD Organization has demanded a ransom of 30 Bitcoin, approximately $1.9 million, and has begun leaking samples of the stolen data, including passport scans. The university is working with cybersecurity experts and law enforcement to investigate and recover systems, a process expected to take weeks to months. Mount Royal University is offering two years of credit monitoring and identity theft protection to affected individuals. Source: Bleeping Computer An In-Depth Guide to Ransomware Get essential knowledge and practical strategies to protect your organization from ransomware attacks. Learn More SC Staff Related Breach AssuranceAmerica confirms data breach affecting 6.9 million driver’s licenses SC Staff July 9, 2026 AssuranceAmerica discovered unauthorized access to its systems on March 17, concluding its investigation on June 15. Malware New GoodPersonRAT malware distributed via fake LetsVPN installer SC Staff July 9, 2026 The trojanized installer, identified as Kuailian_win-setup.86.msi, embeds a loader and an encrypted payload alongside the authentic LetsVPN application. Malware Armored Likho APT leverages AI-generated malware and BusySnake Stealer SC Staff July 9, 2026 Armored Likho utilizes a modular and evolving toolkit that includes obfuscated remote access trojans (RATs), the Python-based BusySnake Stealer, and Go2Tunnel for network tunneling. Related Events Cybercast Ransomware reloaded: Finding resilience when attackers wield AI On-Demand Event Virtual Conference Ransomware Resilience: Strategies to Defend, Mitigate, and Recover On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds