A university in Winnipeg has released more details about the impacts of an apparent cyberattack last month. Canadian Mennonite University (CMU) said they became aware of an “unknown third party” accessing their IT systems without authorization on Sept. 18 and confirmed information was stolen from their systems. “We have now confirmed that the data stolen likely includes the personal information of a range of current and former students and employees,” CMU president Cheryl Pauls wrote in a letter dated Oct. 2. Information stolen includes T4 forms for current and former employees who worked at the post-secondary institution between 2015 and 2025. It also includes T2202 forms for current and former students who attended CMU between 2019 and 2025, and T4A forms for students who attended between 2023 and 2025. Names, social insurance numbers and home addresses are among the information exposed following the cyberattack. A full list of impacted groups can be found on the school’s website. “We are dismayed that education institutions among many other organizations that serve society are often targeted by cyberattacks,” Pauls wrote. CMU has arranged to provide all affected current and former students and employees with a complimentary credit monitoring service for two years in an attempt to protect them from fraud and identity theft. All eligible individuals will receive an email, but the university says those who haven’t received one by Oct. 9 are asked to email privacyquestions@cmu.ca.