On October 2, 2026, the Booba Project ransomware group added the University of Illinois Chicago (UIC) to its leak site. The group says it stole 344 GB of data. UIC is a major public research university in the US and runs a large academic medical center. Every source available for this brief is a third-party tracker or aggregator. None is a statement from the university or a regulator filing. As of publication, UIC has not publicly confirmed the incident (Yazoul, DataBreachRights). This brief treats the listing as an unverified claim by a criminal group that benefits from pressuring its victim. Separate infostealer telemetry cited by QPulse suggests that thousands of UIC-linked credentials were already circulating before the listing appeared.
What Happened
Three trackers report the same 344 GB figure, all from the group's own post: QPulse (citing Ransomware.live), Yazoul and DataBreachRights. Yazoul says the post describes the material as "Higher Education Stolen data." It also says the post includes no data samples, file listings or proof of exfiltration. No source reports encryption, outages or disruption to university or hospital operations. QPulse says it cannot confirm the current status of UIC's systems or any remediation work.
UIC appeared on the leak site during a busy stretch for the group. On the same day, October 2, UXC News reported that Booba Project also claimed Raleigh Family Medicine. ThreatMon alerts, reported by Undercode News, show the group listing GOTTHELF on September 22 and COSEF, an Italian economic development consortium, on September 23. SOCRadar counted 10 Booba Project victims in the 60 days before August 24, 2026. Most were in the United States, Russia and Mexico, and they spanned business services, professional services and technology. General trackers such as Trinetra's live ransomware map collect public leak-site listings like this one, but they add nothing specific to UIC.
Accounts of the group itself differ. Yazoul calls Booba Project an operation with "limited public documentation": it has no catalogued toolset, no detection signatures and no established victim count. SOCRadar describes a group with a recognisable targeting pattern and a known initial-access method. UXC News says the group has "previously targeted hospitals and clinics across the United States." No other source supports that claim, so treat it with caution.
What Was Taken
The only volume figure is the group's own: 344 GB. No source has seen the contents. DataBreachRights lists names and contact information, student records, employee personnel files, financial aid data, Social Security numbers and academic transcripts as exposed. That list appears to describe what a university typically holds. Nothing published by the actor backs it up, so readers should not take it as confirmed. No source says patient or clinical data from UIC's medical center was taken. If it was, the incident would trigger HIPAA notification requirements in addition to FERPA and state breach law.
A separate dataset adds context. QPulse cites an exposure report from ParanoidLab that ties infostealer infections to UIC-linked identities:
- 521 employee accounts, 1,932 user accounts and 609 third-party employee credentials compromised
- 221,582 exposed passwords, 3,802 of them rated critical
- 1,745 exposed session cookies, 17 of them rated critical
- 166 exposed items found in attack-surface analysis
- "Cavalier" named as the infostealer family in the distribution data
These figures describe credential exposure, not data stolen in the ransomware incident. Only one source reports them, and no source links them directly to the claimed intrusion.
Why It Matters
Universities with medical centers combine an open academic network, a large and constantly changing population of students and staff, and regulated health data. Users log in to a long list of SaaS services from personal devices. QPulse lists Atlassian, Autodesk, Brevo, Canva, Cisco, Jamf, Miro, Notion, OpenAI and Zoom in UIC's external attack surface. Each is a place where a stolen session cookie or reused password can work. The 609 exposed third-party employee credentials suggest that contractors and vendors also widen the risk.
The infostealer-to-ransomware pipeline also lowers the bar for groups with little public profile. A group with no custom exploits can still reach a large institution if it buys the right logs. Whether or not the 344 GB claim holds up, the reported credential exposure is a risk on its own.
The Attack Technique
UIC has not confirmed how the attackers got in, if they did. Two sources point toward stolen credentials:
- SOCRadar says Booba Project operators typically buy infostealer logs on underground markets. They then test the credentials against Microsoft 365, VPNs and remote-access portals before deploying ransomware.
- QPulse says the UIC incident "appears to be facilitated by infostealer activity," citing the ParanoidLab data above. This is an inference from exposure data, not forensic evidence.
UXC News lists phishing attachments, unpatched medical device vulnerabilities and weak or reused remote-access passwords as Booba Project methods. It gives no evidence, and the list reads as generic. Overall, credential-based access is the most likely explanation, but it is unconfirmed.
What Organizations Should Do
- Check infostealer exposure for your domains. Search stealer-log feeds for corporate, student and vendor accounts. Force password resets and revoke active sessions for any account that appears, including the accounts of the personal devices behind them.
- Treat session cookies as credentials. Shorten token lifetimes for SaaS and identity providers. Bind sessions to devices where your platform supports it. Re-authenticate users after any infostealer detection.
- Require phishing-resistant MFA at every entry point. That includes VPN, Microsoft 365, remote-access portals and SSO-connected SaaS. Remove legacy authentication that bypasses MFA.
- Bring vendor and contractor identities under control. Inventory third-party accounts, require MFA and conditional access for them, and expire unused access automatically.
- Watch for large outbound transfers. A 344 GB theft would be a large outbound flow. Alert on unusual egress from file shares, research storage and clinical systems.
- Prepare for extortion follow-up. Expect phishing that references the incident to target students, staff and patients. Plan notification paths under FERPA, HIPAA and state breach laws before you know for sure that data was taken.
Sources: University of Illinois Chicago Targeted by Booba Project Ransomware... | University of Illinois Chicago Ransomware Claim by Booba Project (O... | Trinetra Threat Intelligence Live global ransomware map | University of Illinois Chicago Data Breach: What to Know | Booba Project and Kairos Add New Victims as Ransomware Activity Con... | Booba Project ransomware group claims Raleigh UXC News | Davroc Data Breach Technology Data Breach Intelligence SOCRadar®... | Two New Ransomware Victim Claims Emerge: Booba Project and Arcusmed...