PrivacySignal
Breach

Mount Royal University confirms breach as hackers claim attack

BleepingComputer · · International · Data Breaches

Mount Royal University in Calgary has confirmed that attackers breached its network, stole data from file storage systems, and then deleted it. The university disclosed the incident after hackers publicly claimed responsibility for the attack.

Why this matters: Universities collect a lot on the people inside them — student records, financial aid details, health accommodations, research data, staff personnel files. When attackers steal and then delete data, the deletion is pressure, not cleanup. It is a way to force a response. Students and staff at Mount Royal had no say in how their data was stored or secured. Now they are waiting to find out what was taken. That accountability gap is the real problem here, and it is common to nearly every campus breach.

Who should care: Cybersecurity · Privacy officers · Administrators

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
DataBreaches.net · · International

Connecticut says data from 41,000 Medicaid members exposed in portal breach; the second portal incident this year

Connecticut's Medicaid provider portal suffered a breach exposing payment and claims data for roughly 41,000 HUSKY Health members, detected on June 25, 2026. The vendor Gainwell Technologies, which manages the state's Medicaid fiscal operations, is at the center of the incident — the second portal breach Connecticut has reported this year.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
BleepingComputer · · International

Hackers infect Android car head units with proxy botnet malware

A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
CyberScoop · · US Federal

Apollo discloses data breach from ongoing wave of attacks hitting financial sector

Apollo, a major private equity firm, disclosed that attackers accessed some of its cloud platforms over a five-day window in early July, exposing sensitive personal data. The breach is part of a broader wave of cyberattacks targeting financial sector firms.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →
Breach
DataBreaches.net · · International

Troutman Pepper Locke Silent as Threat Actors Leak Client Data, Tens of Thousands of SSNs

In April, Silent Ransom Group’s (SRG)* leak site listed 38 law firms that had not paid them and whose data was leaked. By June 29, there were 48 law firms. Now there are 64, and, in somewhat surprising claims, SRG says a recent attack was actually its second on one law firm, and they will... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
The Record · · International

U.S. Bank says breach claims related to fourth-party incident

U.S. Bank has acknowledged claims of a data breach but says the incident originated with a fourth-party vendor, not its own systems. The bank states there is no evidence that its internal networks or data repositories were directly compromised.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
BleepingComputer · · International

Hundreds of leaked AWS keys give full control over corporate accounts

More than 9,300 AWS access keys exposed publicly over a four-year period remain active and valid, giving anyone who finds them full control over the corporate cloud accounts they belong to. The keys were accessible between August 2022 and August 2026.

Who should care: Cybersecurity · Privacy officers · Administrators