Mount Royal University Confirms Data Breach After Hackers Stole and Deleted File‑Storage Content
What Happened — Hackers breached Mount Royal University’s network on June 17, accessed the “H” drive, exfiltrated files containing personal data of students, staff and other individuals, and then wiped the “J” drive to impede recovery. The attackers are demanding a 30 BTC ransom and have threatened public release of the stolen material.
Why It Matters for Compliance & Audit Readiness
- The incident exemplifies a failure of access‑control and monitoring safeguards that SOC 2’s Security and Confidentiality principles require.
- Continuous evidence of privileged‑access reviews, file‑system activity logging, and incident‑response playbooks is essential to demonstrate due diligence during an audit.
- Verisq’s SOC2 Access Controls capability can provide the audit‑ready evidence you need to prove that access policies, least‑privilege enforcement, and real‑time monitoring are in place.
Who Is Affected – Higher‑education institutions, public‑sector universities, and any organization that stores personal data on shared network drives.
Recommended Actions
- Map the breach to SOC 2 CC6.1 (Logical Access Controls) and CC6.2 (User Access Reviews); verify that privileged‑access logs are collected and retained.
- Deploy continuous monitoring of file‑share activity and integrate alerts into your security‑information‑and‑event‑management (SIEM) platform.
- Update incident‑response playbooks to include forensic preservation of deleted data and coordinated notification to privacy regulators.
Source: BleepingComputer
Technical Notes – Attack vector not publicly disclosed; likely a network‑penetration leading to credential compromise. Stolen data includes passport scans and other personally identifiable information (PII). No specific CVE cited. Source: same article