
October 2, 2026
Dear present and past members of the CMU learning community,
On Friday, September 18, 2026, Canadian Mennonite University became aware of a cybersecurity incident during which an unknown third party accessed our IT systems without authorization. Regrettably, we recently confirmed that the third party used their access to steal information from our systems.
We immediately initiated our incident response plan, retained expert assistance, and informed the University community whose workflows were affected as soon as we became aware of the incident. We also reported this incident to law enforcement and will be filing a report with the Office of the Privacy Commissioner of Canada.
We have been investigating the incident under the guidance of our experts. We have now confirmed that the data stolen likely includes the personal information of a range of current and former students and employees. The investigation is ongoing, and our findings to date are not final. However, we have identified several groups who are likely affected. We summarize the affected groups of individuals and their exposed information below.
We have arranged to provide all affected current and former employees and students with a complimentary two-year credit monitoring service so that they may protect themselves. All eligible individuals will receive an email, through the most recent contact information we have on file, containing instructions about how to access this credit monitoring service. If you believe you are eligible for this credit monitoring service but have not received an email from us by Friday, October 9, please contact: privacyquestions
We encourage all eligible current and former staff, faculty, and students to enrol in the credit monitoring service. Accessing this service is important and provides good protections against harms like identity theft and fraud.
We are dismayed that education institutions among many other organizations that serve society are often targeted by cyber-attacks. These incidents are very hard on communities, and the impacts of this violation on the CMU learning community extend from present students and employees to a range of former students, staff, and faculty.
We are grateful for the CMU staff members who have been working very long days to secure and restore our systems, and to everyone in the CMU community for sustaining their good work of exceptional education, operations, and overall well-being through the disruption.
Please direct all inquiries on the incident to: privacyquestions
An update will be provided once our investigation is complete.
Respectfully yours,

Cheryl Pauls, President
Canadian Mennonite University
Printed from: media.cmu.ca/incident-notice