Full Breakdown
Cyberattack Exposes Personal Data of Thousands at Canadian Mennonite University
By Drooid · · How we work
Core Event
In September, Canadian Mennonite University (CMU) detected an unauthorized intrusion into its information-technology systems. An “unknown third party” accessed records that included names, mailing addresses, social insurance numbers and tax-form details (T4 and T2202) for current and former students, staff and faculty. The university promptly shut down affected systems and activated its incident-response plan.
Background & Context
CMU’s breach follows a series of cyber incidents targeting Manitoba institutions. Two years earlier, the University of Winnipeg, Pembina Trails School Division and the provincial families department were compromised. Earlier this year, the Rural Municipality of Gimli and Winnipeg’s Health Sciences Centre experienced similar attacks. University officials note that each incident has prompted internal reviews and system upgrades.
Data & Statistics
- Initial estimates indicated that just under 4,000 individuals were potentially affected.
- Subsequent analysis determined that roughly 20 % of those records were not actually compromised, leaving about 3,200 people whose personal data may have been accessed.
- The breach spans a ten-year period (2015-2025) for T4 tax forms and a shorter window for T2202 tuition-credit forms.
Official Statements & Responses
President Cheryl Paul Pauls said the intrusion was carried out by an unwarranted third party with malicious intent. CMU immediately enacted its critical-system response plan, engaged cybersecurity experts through its insurance provider, and reported the incident to law-enforcement and the Office of the Privacy Commissioner of Canada. The university has posted a notice on its website, mailed letters to those affected, and is offering a complimentary two-year credit-monitoring service to all eligible current and former students, staff and faculty. The investigation remains ongoing.
Verbatim Quotes
- “An unwarranted third party with intention to do harm got into the system,” — Cheryl Pauls, says university president
- “We immediately closed down whatever we could while we were checking … and immediately got our critical system response plan in action,” — Cheryl Pauls, says university president
- “We immediately initiated our incident response plan, retained expert assistance, and informed the university community whose workflows were affected as soon as we became aware of the incident,” — Cheryl Pauls, says university president
- “We also reported this incident to law enforcement and will be filing a report with the Office of the Privacy Commissioner of Canada.” — Cheryl Pauls, says university president
- “We encourage all eligible current and former staff, faculty, and students to enrol in the credit monitoring service. Accessing this service is important and provides good protections against harms like identity theft and fraud,” — Cheryl Pauls, says university president
