Mount Royal University staff are working alongside law enforcement to control a recent cyberattack that unfolded earlier in June, leaving most of MRU’s webpages, including student and faculty portals, inaccessible. The school has now confirmed that the incident was a ransomware attack. In addition, MRU said the attack primarily affected the school’s “H drive,” a shared drive used to store digital data for both students and staff.
“Data contained within those folders was accessed and taken by the actor, most likely in the days leading to our discovery of the incident on June 17. The actor then deleted our H drive data to impede our recovery,” MRU said in a statement on Friday.
Brenda Lang, president of the Mount Royal Faculty Association, advised faculty members on how to initiate the recovery process but noted that some folders contained decades of data, making the process challenging.
“Some of us have stored materials on our H drive for several years, so it is impossible to provide an accurate number of students whose names, ID numbers, email addresses, and grades were included in the files,” Lang said in an email to colleagues.
MRU urges caution
Another drive, containing corporate data for MRU staff and services, was also deleted during the incident which contains crucial institutional information.
Sensitive information, such as banking statements, may be among the data included in the ransomware attack. MRU has advised those affected to be cautious of unexpected emails or calls, and to monitor bank, credit card, or other financial accounts for unusual activity.
MRU’s incident support team said that the ongoing investigation and data recovery could take several months to complete.
