Baseline Controls News Resources Glossary About

Canadian Mennonite University Data Breach: Tax Data Retention Lessons

Canadian Mennonite University Data Breach: Tax Data Retention Lessons

A cyberattack at Canadian Mennonite University, discovered on September 18, 2026, exposed employee T4 forms dating back to 2015 and student tuition records from 2019 onward. The Winnipeg-based university confirmed on October 7 that an unknown third party accessed its IT systems and stole data containing social insurance numbers, addresses, earnings, and tax information for current and former employees and students. The university reported the incident to law enforcement and stated it will file a report with the Office of the Privacy Commissioner of Canada.

For Canadian organizations that handle employee payroll or student financial records, this incident is a case study in how data retention decisions made years ago can determine the scope of a breach today.

What Data Was Stolen in the CMU Cyberattack?

According to the Winnipeg Free Press, which reported on CMU President Cheryl Pauls' statement on October 7, 2026, the stolen data includes multiple categories of tax and employment records spanning up to 10 years:

  • T4 forms for current and former employees from 2015 to 2025, containing names, addresses, social insurance numbers, employer names, employee numbers, and earnings
  • T2202 tuition forms for current and former students from 2019 to 2025, with names, addresses, social insurance numbers, enrolment information, and tuition fees
  • T4A scholarship forms for students from 2023 to 2025, listing names, addresses, SINs, and scholarship or bursary values
  • TD1 Personal Tax Credits Return forms from 2023 to 2026, including dates of birth and tax deduction details
  • Records of employment for 2020 and 2023 to 2026, showing days of employment, insurable earnings, and vacation payouts

The university has 775 students enrolled for 2026, plus 40 faculty and 50 part-time instructors, according to the Canadian Underwriter. However, the breach affects a much larger group: anyone whose records were retained from as far back as 2015.

Why Does Retaining Tax Records for 10 Years Increase Breach Risk?

The CMU breach illustrates a straightforward principle: the longer you retain sensitive data, the more individuals are exposed if that data is stolen. CMU's T4 records spanned 10 years. Every former employee who worked at the university between 2015 and 2025 is now affected, including people who left years ago and may have no current relationship with the institution.

According to the CRA's record retention guidance, organizations must generally keep records for six years from the end of the last tax year they relate to. That means 2018 T4s could have been destroyed after December 31, 2024. Records from 2015, 2016, and 2017 could have been securely deleted even earlier.

This is not a criticism specific to CMU. Many Canadian organizations retain data far longer than regulations require, often because deleting old records feels risky or because no one has been tasked with a formal retention schedule. The CMU incident shows the cost of that default: the total number of affected individuals was not publicly disclosed, but the breach extends to anyone whose records were retained from as far back as 2015, including people who may have left the university years ago.

What Should Affected Individuals Do Now?

CMU is offering two years of complimentary credit monitoring to affected current and former students and employees, according to the Winnipeg Free Press. Those eligible will receive an email to their most recent contact information on file. The university advised that eligible individuals who did not receive an email by Friday (October 9, 2026) should contact privacyquestions@cmu.ca.

Beyond credit monitoring, individuals whose SINs were exposed should:

  1. Place a fraud alert with both major Canadian credit bureaus (Equifax Canada and TransUnion Canada). This adds a verification step when new credit is applied for in your name.
  2. Monitor your CRA account for any unauthorized changes or unfamiliar filings. Tax-related identity fraud often surfaces during tax season when criminals file false returns to claim refunds.
  3. Treat any communication referencing CMU, CRA, or tax refunds with suspicion for the next several months. Attackers who have your SIN, address, and employer details can craft convincing phishing.
  4. Report suspected identity fraud to the Canadian Anti-Fraud Centre at 1-888-495-8501 or antifraudcentre-centreantifraude.ca.

For more on what to do after your data is exposed, see our guide on what to do in the first 24 hours after a cyber attack.

What Are the PIPEDA Breach Reporting Requirements?

CMU stated it will file a report with the Office of the Privacy Commissioner of Canada. Under PIPEDA's mandatory breach reporting rules, private-sector organizations engaged in commercial activity must report any breach involving personal information that creates a "real risk of significant harm" to individuals. CMU is a private university in Manitoba, and the extent to which PIPEDA applies to its handling of student and employee data depends on the nature of that activity. (Some provinces have their own substantially similar privacy legislation for private-sector organizations.)

For businesses clearly subject to PIPEDA, the breach reporting obligations are:

  • Report to the OPC as soon as feasible after determining that a breach creates a real risk of significant harm
  • Notify affected individuals directly, with specific information about what happened and what steps they can take
  • Keep records of all breaches for at least two years, regardless of whether the breach meets the reporting threshold

The CMU breach also illustrates why incident response planning matters. The university detected the incident on September 18 and made a public disclosure on October 7, roughly 19 days later. That timeline allowed for investigation and confirmation of the stolen data before notifying the public. Organizations without a documented incident response plan often take longer to respond, extending the window during which affected individuals are unaware their data is at risk.

How Should Canadian Organizations Rethink Data Retention?

The CMU breach is a prompt for every Canadian organization that handles payroll, tuition, or tax-related records to ask: how long are we keeping this data, and is that necessary?

A practical data retention policy should account for:

  1. Regulatory minimums: The CRA generally requires six-year retention for records from the end of the last tax year they relate to. Know your specific obligations.
  2. Regulatory ceilings: Once the retention period expires, there is usually no requirement to keep the data. In many cases, deleting it reduces your liability and breach exposure.
  3. Operational needs: Some data may be needed for pension calculations, historical reporting, or legal disputes. Identify specific use cases rather than retaining everything by default.
  4. Secure deletion: When retention periods expire, data should be destroyed in a way that prevents recovery. This means secure wiping of digital records and shredding of physical documents.

Our page on data backup and recovery addresses the flip side of this issue: ensuring critical data is backed up and recoverable. But retention policies work in the opposite direction, determining what should not be kept once its useful life ends.

How Does This Incident Connect to the Baseline Controls?

The CMU breach does not disclose the specific technical vector used by the attackers. What the incident does reveal is the downstream consequence of data that accumulates over years without a formal retention policy.

Several of the Canadian Centre for Cyber Security's 13 Baseline Controls are relevant to preventing or limiting this kind of breach:

  • Access control: Limit who can access sensitive records. Payroll and tax data should be accessible only to staff with a documented business need.
  • Secure configuration: Systems storing SINs and tax records should be hardened against unauthorized access.
  • Incident response: A documented plan reduces the time between detection and notification.
  • Security training: Staff who handle sensitive data should understand phishing, credential theft, and the risks of poor data hygiene.

None of these controls directly addresses retention policy, but all of them become more important the longer sensitive data is stored. A decade of T4s is a larger target than six years of T4s.

What Is the Next Step for Your Organization?

If your organization retains employee payroll data, student financial records, or any information containing SINs, use the CMU incident as a prompt to review your practices:

  1. Audit what you are retaining and for how long. You may find records well past their required retention period.
  2. Establish or update a written retention policy with clear timelines for each data category.
  3. Implement secure deletion procedures for data that has aged out of the retention window.
  4. Test your incident response plan to ensure you can detect, investigate, and report a breach within a reasonable timeframe.

Our free cybersecurity assessment evaluates your organization against all 13 Baseline Controls, including access control, incident response, and data protection measures. It runs entirely in your browser, collects no data, and gives you a prioritized view of where your security posture needs attention.

One question to ask your IT provider this week: "If we had a breach tomorrow, how far back would our exposed payroll and tax records go?"

The answer to that question determines how many people you would have to notify.

Free Assessment

How prepared is your business?

Find out where you stand against Canada's 13 Baseline Cyber Security Controls. The assessment takes under 30 minutes and your answers stay in your browser.

Check Your Score

Frequently Asked Questions

What happened in the Canadian Mennonite University cyberattack?

On September 18, 2026, Canadian Mennonite University discovered unauthorized access to its IT systems. The university confirmed that an unknown third party stole data including T4 forms from 2015 to 2025, T2202 tuition forms from 2019 to 2025, and records of employment going back to 2020. Exposed information includes social insurance numbers, addresses, earnings, birth dates, and tax deduction details.

How many years of data were exposed in the CMU breach?

Employee T4 forms going back 10 years (2015 to 2025) were exposed. Student T2202 tuition forms covered 2019 to 2025, and TD1 tax credit forms spanned 2023 to 2026. The extended retention period significantly increased the number of individuals affected, including people who may no longer have any connection to the university.

Does PIPEDA require organizations to delete old tax records?

For private-sector organizations engaged in commercial activity, PIPEDA's retention principle states they should keep personal information only as long as necessary for the identified purpose. However, this must be balanced against Canada Revenue Agency requirements: employers must generally keep records for six years after the taxation year to which they relate. Once the CRA retention period expires, there may be no requirement to keep the data, and doing so increases breach exposure.

Cite This Page

Suggested citation:

Cybersecurity Canada (2026). Canadian Mennonite University Data Breach: Tax Data Retention Lessons. Retrieved from https://cybersecuritycanada.ca/news/posts/canadian-mennonite-university-data-breach-lessons-for-tax-data-retention/

Disclaimer: This article is intended for general informational purposes only and does not constitute professional cybersecurity, legal, IT, or compliance advice. While we strive to ensure accuracy, the cybersecurity landscape changes rapidly and information may become outdated. Organizations should consult with qualified cybersecurity professionals and legal counsel to assess their specific situation and develop appropriate security policies. Use of this information is at your own risk. See our Privacy Policy for more information.

Cybersecurity Canada is an independent resource and is not affiliated with, endorsed by, or connected to the Canadian Centre for Cyber Security, the Communications Security Establishment, or the Government of Canada.

How does your organization measure up?

Take our free cybersecurity assessment based on the Canadian Centre for Cyber Security's Baseline Controls. 50 questions, under 30 minutes, 100% confidential. Your answers never leave your browser.

Take the Free Assessment