
An unknown third party accessed Canadian Mennonite University’s IT systems without authorization. CMU discovered this incident on September 18, 2025. Unfortunately, CMU confirmed that the unauthorized actor stole data from our systems, including data about current staff and students.
We are taking care to ensure the accuracy of any information we provide. Providing incomplete or inaccurate information could cause confusion or unnecessary concern, so we are prioritizing careful, verified updates. We will be publishing updates, including updates about who was affected by this incident, at media.cmu.ca/incident-update (webpage available soon).
Yes. This incident involved a ransomware threat actor. We are working with cybersecurity and threat intelligence experts to assess the situation and manage risk.
The incident affected our on-premises systems. We have no evidence that our cloud-based systems, such as email, were affected by this incident, and remain operational.
We have contained the incident, engaged leading external cybersecurity and forensic experts, initiated a detailed investigation, and implemented additional security measures. We will also be offering credit monitoring to eligible individuals by end of day on October 9, 2026. Finally, we have reported this incident to the Canadian Anti-Fraud Centre and the Winnipeg Police Service and will be reporting this incident to the Office of the Privacy Commissioner of Canada.
We understand that information about current and former students and staff was taken. We will be publishing updates, including more information about who was affected by this incident at media.cmu.ca/incident-update (webpage available soon). Our analysis is ongoing, and we will provide further updates as our investigation continues.
Identity fraud is unfortunately a risk that all individuals face in today’s digital environment, regardless of any particular incident. For that reason, it is always a good idea to take common-sense precautions to protect your personal information. These include monitoring your financial accounts and credit reports, being vigilant about unsolicited communications, and using strong, unique passwords. Employees and students who receive credit monitoring offers should enrol.
Yes. We are committed to protecting your information and are taking steps to strengthen our safeguards.
Our cloud-based systems are currently operational. You can continue to access applications like our email system (including SharePoint and OneDrive), Populi, Slate, FENXT, RENXT, and Avanti.
We are working to ensure that our on-premises systems are restored as quickly as possible, while ensuring that they are safe to use.
Please contact our IT team at helpdesk
We have no evidence that any student account was compromised. CMU will let students know when their passwords need to be reset.
You can contact our dedicated response team at privacyquestions
Yes. We will continue to provide updates as new information is confirmed.
Although we have no evidence that any stolen data was published, we encourage you to register for the credit monitoring service that we will be distributing during the week of October 5. If you have not received an email from us instructing how to register for this service by end of day on Friday, October 9, 2026, please let us know.
We also encourage you to consult the following resources if you have more questions about how to protect yourself:
Assuming you are an individual eligible for credit monitoring, we have published the categories of affected information on our webpage dedicated to updates about this incident. Although we have no evidence that any stolen data was published, we encourage you to register for the credit monitoring service that we will be distributing this week. If you have not received an email from us describing how to register for this service by end of day on Friday, October 9, 2026, please let us know.
Students who began their studies in 2026, are CMU employees, and submitted a TD1 Personal Tax Credits Return and Manitoba Personal Tax Credits Return forms were affected by this incident.
Even though the information of new students who are not employees was not exposed, CMU is offering credit monitoring to all current students regardless.
For more information about the information exposed, please consult our webpage dedicated to updates about this incident: media.cmu.ca/incident-update (webpage available soon).
At this point, we will be providing credit monitoring to the individuals affected according to the breaches details in the announcement about the September 18, 2026 cyber attack. See media.cmu.ca/incident-notice.
If you have registered for the credit monitoring service we provided, we also encourage you to consult the following resources if you have more questions about how to protect yourself:
CMU reported this incident to the Canadian Anti-Fraud Centre (report # 2026-D8QW-SZC5-W) and the Winnipeg Police Service (report #E260032743).
We have not found any evidence that individuals’ banking information was compromised. We will be publishing updates, including updates about who was affected by this incident, at media.cmu.ca/incident-update (webpage available soon). Our analysis is ongoing, and we will provide further updates as our investigation continues.
CMU is required to retain personal information for various reasons, including to comply with tax and other legal obligations
CMU will not be alerting your bank regarding this incident. You may do so if you wish.
The TransUnion credit monitoring service provides good protection. It also includes other ancillary services. For more information about the services that are included with the credit monitoring service, please consult the end of the email we sent to you on October 6–9, 2026.
The TransUnion credit monitoring service provides good protection. If you would like, you may contact TransUnion or Equifax to request that a fraud alert (for your TransUnion credit file) or identity alert (for your Equifax credit file) be placed on your credit file.
Try to retrieve the email from your deleted items folder or contact privacyquestions
Please contact TransUnion Canada for support at 1.888.228.4939. It is likely that when registering for the service the authentication step failed.
Please contact TransUnion Canada for support at 1.888.228.4939. It is likely that when registering for the service the authentication step failed.
Printed from: www.cmu.ca/about/incident-faq