A ransomware group just hit a Calgary university, stole 10 terabytes of data, deleted the originals, and is demanding $1.9 million. If your Edmonton or Alberta business thinks this doesn’t apply to you, read on — because the group behind it specifically targets organizations that look easier than large enterprises.
On June 17, 2026, Mount Royal University in Calgary discovered that attackers had broken into their network, accessed shared file storage used by both students and employees, copied the contents, and then deleted the originals. <cite index=”11-1″>The attack disrupted a broad range of university systems, including online services, internet access, and certain internal systems.</cite> <cite index=”13-1″>A ransomware group called CMD Organization added MRU to its leak site, claiming the theft of over 10 terabytes of data and demanding a $1.9 million ransom.</cite>
This isn’t just a story about a university. It’s a story about a new type of attack that every Alberta organization — including Edmonton businesses — needs to understand.
Who Is CMD Organization?
<cite index=”6-1″>CMD Organization is an emerging ransomware group that first posted victims to their public leak site in early April 2026.</cite> <cite index=”8-1″>It operates a ransomware-as-a-service scheme in which affiliates pay to use CMD’s malware and infrastructure to launch attacks and collect ransoms.</cite>
What makes CMD different from most ransomware groups is their monetization model. <cite index=”6-1″>By adding a bidding platform within its leak site, the group allows potential buyers to participate directly in the extortion process alongside victim negotiations.</cite> In other words, they don’t just demand a ransom from the victim — they also auction the stolen data to whoever wants to buy it. The victim faces pressure from two directions simultaneously: pay the ransom, or watch their data get sold to the highest bidder on a public platform.
<cite index=”9-1″>CMD Organization is a relatively new gang but it’s quickly gaining notoriety with some hefty ransom demands and crippling attacks. CMD has claimed responsibility for 32 ransomware attacks since it began, across 10 countries. Its average ransom demand is $580,000.</cite> The MRU demand of $1.9 million is more than three times that average.
The Delete-After-Steal Tactic: Why This Attack Is Different
Most ransomware works by encrypting your files and offering a decryption key in exchange for payment. Organizations with proper backups can often restore their systems without paying — which is why we’ve consistently emphasized tested, isolated backups as the foundation of any cybersecurity strategy, as covered in our data backup and recovery guide.
The MRU attack used a different and significantly more damaging approach. <cite index=”10-1″>The delete-after-steal tactic eliminates that exit: the attacker’s copy is the only copy remaining. Any specific file that was on the H drive but was not independently replicated elsewhere is irretrievably gone unless MRU pays and CMD Organization actually delivers a restoration.</cite>
<cite index=”11-1″>The actor also deleted MRU’s “J drive,” which contains corporate data about MRU staff. While the school is working to recover the deleted J drive data, it said a full recovery may not be possible.</cite>
This is why immutable backups — backups that cannot be modified or deleted even by someone with admin access — have become an essential part of a complete backup strategy, not just a nice-to-have.
How CMD Got In: An SEO Poisoning Attack
The initial access method documented by security researchers reveals how sophisticated and yet how avoidable this type of attack is. <cite index=”6-1″>Initial access was achieved through an SEO-poisoned lure within Bing’s search ecosystem, tricking the victim into downloading a fake PDF in the form of an archive. The archive contained a malicious, encoded JavaScript loader.</cite>
In plain terms: someone searched for something on Bing, clicked what looked like a legitimate result, downloaded what appeared to be a PDF, and inadvertently installed malware. <cite index=”6-1″>Multiple weeks of dwell time were observed between initial access and ransomware deployment</cite> — meaning the attackers were inside the network for weeks before anyone noticed, quietly moving through systems and positioning themselves before striking.
This attack vector — a poisoned search result leading to a malicious download — is exactly the kind of thing that endpoint protection and employee security awareness training are designed to catch. It’s also the kind of thing that phishing and social engineering awareness covers, because the mechanism is the same: an employee clicks something they shouldn’t, and the attacker gains a foothold.
The Data Exposure: Who Was Affected
<cite index=”13-1″>MRU confirmed that a ransomware group was behind the attack and that employee and student data hosted on its H drive was exfiltrated and deleted. The H drive is a file storage system used by individual employees and students.</cite>
<cite index=”8-1″>The university is offering employees two years of credit monitoring and identity theft protection services.</cite> However, that protection was not initially extended to students — despite the fact that <cite index=”10-1″>CMD Organization posted passport scans on its extortion site, and a passport belonging to a student carries the same identity fraud risk as one belonging to an employee.</cite>
<cite index=”15-1″>Mount Royal University reported the incident to the Alberta Office of the Information and Privacy Commissioner.</cite> Under Alberta’s PIPA, this type of breach — involving personal information that creates a real risk of significant harm — triggers mandatory notification obligations. For any Alberta organization handling personal data, the MRU breach is a direct illustration of what those obligations look like in practice.
What This Means for Edmonton and Alberta Businesses
The MRU attack is not an isolated incident affecting only universities. CMD Organization has hit <cite index=”9-1″>32 victims across 10 countries</cite> since emerging earlier this year. They are actively targeting Alberta organizations, and the tactics they used at MRU — SEO poisoning, long dwell time, data theft followed by deletion — work just as effectively against a mid-sized Edmonton business as against a university.
Several elements of this attack are directly relevant to how Alberta businesses should think about their security:
Backups alone aren’t enough anymore. The delete-after-steal tactic specifically targets and destroys backups before or alongside the exfiltration. Immutable offsite backups — stored in a location that cannot be deleted remotely — are the only defense against this specific move. This goes beyond standard backup advice and into backup architecture decisions your IT provider needs to make deliberately.
Long dwell times mean detection matters. The attackers were inside MRU’s network for weeks before deploying ransomware. During that time, active monitoring with behavioral detection — not just antivirus — could have flagged the reconnaissance activity, the lateral movement, and the data access. This is the difference between a managed IT provider with real security monitoring and one that just maintains your systems.
Employee security awareness is a primary control. The initial access happened because someone clicked a malicious download from a search result. This isn’t a failure of technical controls alone — it’s a gap in employee awareness that no firewall or antivirus fully covers. As we covered in our guide on what to do if your Edmonton business gets hacked, the most effective defense combines technical controls with a team that knows how to recognize and report suspicious activity.
Cyber insurance coverage needs to be reviewed. A $1.9 million ransom demand is beyond what most SMBs can absorb without insurance. As we covered in our cyber insurance guide, cyber insurance coverage requirements have tightened significantly — and the controls required to qualify for coverage are exactly the controls that would reduce your risk of becoming a CMD target in the first place.
What Alberta Organizations Should Do Right Now
Given the active presence of CMD Organization in Alberta, here are the specific actions worth taking immediately:
Verify your backups are immutable and offsite. Ask your IT provider specifically whether your backups can be deleted or encrypted remotely by an attacker who gains admin access. If they can, that needs to change.
Enable MFA on everything. As covered in our MFA guide, MFA blocks the credential theft that often follows initial access and prevents attackers from moving laterally through systems.
Check that endpoint protection goes beyond antivirus. The malware used in CMD attacks uses obfuscated PowerShell and fileless execution techniques that traditional antivirus frequently misses. Endpoint Detection and Response (EDR) tools are designed for exactly this type of threat.
Train your team on malicious downloads. SEO poisoning — fake results in search engines that deliver malware — is increasingly common. Employees need to know to verify downloads, particularly PDFs and archives from unfamiliar sources.
Know your PIPA obligations before an incident happens. If your organization handles personal information and suffers a breach, you have mandatory notification obligations to affected individuals and the Office of the Information and Privacy Commissioner of Alberta. Knowing the process before an incident makes the response significantly less chaotic.
Frequently Asked Questions
What is CMD Organization? CMD Organization is a ransomware-as-a-service group that emerged in early 2026 and has claimed 32 attacks across 10 countries. They use a double extortion model — encrypting or deleting data while simultaneously auctioning stolen data to the highest bidder. They claimed responsibility for the June 2026 attack on Mount Royal University in Calgary.
How did the MRU hack happen? Initial access was gained through an SEO-poisoned search result that tricked a user into downloading malicious software disguised as a PDF. The attackers then spent weeks inside the network before deploying ransomware, exfiltrating data, and deleting the originals.
Could this happen to a small Edmonton business? Yes. CMD Organization targets organizations across all sectors and sizes. The attack techniques used — malicious downloads, credential harvesting, lateral movement — work equally well against a 20-person business as a university. Smaller organizations are often targeted specifically because they have less mature security controls.
What makes the MRU attack different from typical ransomware? Most ransomware encrypts files and offers a decryption key for payment — organizations with backups can often recover without paying. CMD deleted the original files after stealing them, making recovery impossible without paying unless the organization had truly isolated, immutable backups that the attackers couldn’t reach.
What should Alberta businesses do in response to this attack? Review backup strategy to ensure immutable offsite copies exist, verify MFA is enabled on all accounts, ensure endpoint protection goes beyond standard antivirus, train employees on malicious download risks, and review cyber insurance coverage for adequacy.
GuidePost Can Help
GuidePost Technologies helps Edmonton and Sherwood Park businesses implement the security controls that protect against attacks like the one that hit MRU — immutable backup architecture, endpoint detection and response, MFA enforcement, and employee security training — as part of our cybersecurity services.
Explore our Cybersecurity Services →
Call us at 780-851-5000 to book a free cybersecurity assessment for your Edmonton business.
GuidePost Technologies — Managed IT Services, Cybersecurity, Cloud Computing, and Network Support for Edmonton and Alberta Businesses.

One Reply on “The Mount Royal University Hack: What Every Alberta Business Needs to Know”