The Mount Royal University breach highlights how cyberattacks against education institutions can combine data theft with destructive activity.

The university confirmed that an unauthorized actor accessed and stole data from certain folders on its H drive, a file-storage system used by students and employees. The attacker then deleted the H drive data to make recovery more difficult. MRU also reported that its J drive, used for departmental files, was deleted during the incident.

The investigation is still ongoing, and the exact number of affected individuals has not yet been confirmed. MRU has said it will directly notify people whose information may have been exposed and is offering credit monitoring and identity-theft protection to current employees and those employed by the university within the past five years.

For universities, shared file storage often contains a mixture of student records, employee information, departmental documents, research files, financial records, and operational material. If access controls and monitoring are weak, one compromised account or system can expose large volumes of unrelated data.

Organizations should review file-share permissions, monitor bulk downloads and deletions, maintain offline or immutable backups, and investigate unusual access to shared drives. Recovery planning must also account for destructive attacks where attackers steal data first and then delete files to slow restoration.

The key lesson is that ransomware-style incidents are no longer only about encryption. Attackers may steal data, wipe shared storage, disrupt operations, and then use public leak threats for pressure. Apparently, criminals have discovered multitasking, a development nobody asked for.


Mount Royal University in Calgary says hackers stole and then deleted data from its file storage systems after breaching the university's network. [...]

Source: Mount Royal University confirms breach as hackers claim attack via Bleeping Computer — published 08 Jul 2026.