NEWS

University of Illinois Chicago Hit by Ransomware Attack on Medical School

UIC's College of Medicine confirms a ransomware intrusion; Booba gang claims 344GB stolen, but the claim is unverified and under investigation.

Dylan H.

News Desk

October 5, 2026
7 min read
University of Illinois Chicago Hit by Ransomware Attack on Medical School

UIC College of Medicine Confirms Ransomware Attack, Data Theft Under Investigation

The University of Illinois Chicago (UIC) has confirmed that its College of Medicine was hit by a ransomware attack that resulted in the theft of some information from its servers. A UIC spokesperson said some College of Medicine systems were temporarily unavailable, but the university's main network and patient care delivery at UI Health were unaffected. The ransomware gang Booba, which emerged in late July 2026 and claims to be behind the intrusion, says it stole 344 gigabytes of data — a figure that security researchers caution should be treated with skepticism, since the same exact number has turned up attached to other, unrelated Booba victim claims.


Incident Details

AttributeValue
Victim OrganizationUniversity of Illinois Chicago (UIC), College of Medicine
Estimated Attack DateOctober 2, 2026
Public DisclosureOctober 5, 2026
Claimed GroupBooba (Booba Project)
Claimed Data Volume344 GB (unverified)
Systems AffectedSome College of Medicine servers/systems
Systems NOT AffectedMain UIC network; UI Health patient care delivery
Student Population at RiskCollege of Medicine enrolls roughly 1,300 students
Ransomware Confirmed by UICAttack confirmed; scope of stolen data still under investigation
Encryption ConfirmedNo — Booba's listing describes data theft only, not encryption

How the Attack Unfolded

Detection and Containment

UIC identified the intrusion affecting College of Medicine systems and moved to contain and restore them. A university spokesperson said all affected systems have since been restored, and that the attack caused no disruption to the broader UIC network or to patient care delivered through UI Health, the university's academic medical system. UIC reported the incident to law enforcement and coordinated its recovery with outside agencies as part of the response.

The Booba Claim

Booba posted a listing naming UIC as a victim with an estimated attack date of October 2, 2026, claiming to have exfiltrated 344 GB of data from the university. The group emerged in late July 2026 and had already claimed roughly 49 attacks by the time of the UIC posting. Researchers, including SentinelOne's Brett Williams, assess that Booba is likely a rebrand of the Frag ransomware operation, based on overlapping leak-site infrastructure and negotiation processes. Notably, Booba's post describes data theft only — it does not claim UIC's systems were encrypted, consistent with an extortion-only (rather than classic encrypt-and-extort) operating model.

A Claim Worth Treating Cautiously

Ransomware trackers have flagged Booba's listings as including unverified or, in some cases, fabricated victim claims. The 344 GB figure Booba attached to UIC is identical to the figure the group separately claimed for an unrelated victim, MorseLife Health System, around the same estimated attack date — a pattern that suggests Booba may be reusing stock numbers across listings rather than reporting data actually exfiltrated. In at least one prior case involving a different Booba victim, the targeted organization said it found no evidence that data had actually been removed despite Booba's claims. UIC itself has not confirmed the 344 GB figure or any other volume of stolen data.

What UIC Is Still Determining

UIC said its investigation is ongoing to determine whether personal, research, or academic information was compromised. The university has not yet specified categories of exposed data, a confirmed number of affected individuals, or the method of initial access the attackers used to breach College of Medicine systems. UIC has stated it plans to notify anyone whose information is confirmed to have been stolen once that determination is made.


Impact Assessment

Impact AreaDescription
Operational ImpactTemporary unavailability of some College of Medicine systems; now restored, with no impact on UI Health patient care
Data Exposure RiskUnconfirmed — investigation ongoing into whether personal, research, or academic records were stolen
Student/Staff ImpactUp to ~1,300 College of Medicine students potentially affected, pending investigation findings
Claim ReliabilityBooba's 344 GB figure is unverified and matches a figure reused for at least one unrelated victim
Regulatory ExposurePotential breach-notification obligations under state law and, if research or patient-adjacent data is involved, HIPAA/FERPA considerations
Sector TrendLatest in a wave of 2026 ransomware attacks against U.S. higher-education and healthcare-adjacent institutions

Recommendations

For UIC and Affected Individuals

  1. Wait for official notification from UIC before assuming personal data was exposed — the university has stated it will notify individuals once its investigation confirms what was stolen
  2. Monitor for phishing attempts referencing the incident; threat actors and opportunistic scammers often exploit publicized breaches to craft convincing follow-on lures
  3. Enroll in credit or identity monitoring if and when UIC offers it as part of a formal notification
  4. Watch official UIC and UI Health channels rather than third-party leak-site claims for authoritative updates on scope

For Higher Education IT and Security Teams

  1. Segment research, student-records, and clinical-adjacent systems so a compromise in one college does not expose institution-wide infrastructure — UIC's containment to College of Medicine systems suggests effective segmentation worked here
  2. Maintain offline, tested backups for academic and research systems, not just core administrative platforms, given ransomware crews increasingly target college- and department-level servers
  3. Track emerging and rebranded ransomware brands such as Booba/Frag — new or renamed groups often reuse established affiliate infrastructure and TTPs, making threat-intel sharing across institutions valuable
  4. Validate extortion claims before reacting — treat leak-site postings as unverified allegations until corroborated by forensic evidence, while still activating incident response and legal/regulatory review in parallel

For Security Teams Evaluating Ransomware Claims Generally

  • Cross-reference claimed data volumes against other victims from the same group; identical or round-number figures across unrelated organizations (as seen with Booba's recurring "344 GB" claim) are a red flag for inflated or fabricated claims
  • Treat leak-site listings as marketing, not evidence — ransomware groups have a financial incentive to exaggerate scope to pressure victims and generate press coverage

Key Takeaways

  1. UIC's College of Medicine suffered a ransomware attack that disrupted some of its systems and resulted in the theft of some data; systems have since been restored and UI Health patient care was unaffected.
  2. The Booba ransomware gang, which researchers believe is a rebrand of Frag ransomware, claimed responsibility and alleges it stole 344 GB of data from UIC.
  3. Booba's claimed data volume is unverified — the same exact 344 GB figure was separately attached to an unrelated victim around the same date, a pattern consistent with inflated or templated extortion claims.
  4. UIC's investigation into what specific personal, research, or academic information was compromised, and how many people are affected, remains ongoing.
  5. UIC has reported the incident to law enforcement and says it will notify affected individuals once the scope of stolen data is confirmed.
  6. The incident adds UIC to a growing list of U.S. higher-education institutions targeted by ransomware in 2026, underscoring the value attackers place on academic, research, and student data.

Sources