The University of Illinois Chicago (UIC) has confirmed that a ransomware attack took some College of Medicine systems offline and that the attackers took data from the college's servers. In a letter to the campus community, the university said its main network was not affected and patient care at UI Health continued without disruption. A ransomware group called Booba claimed the attack the week before UIC confirmed it. The group says it stole 344 GB of data. UIC has not confirmed that figure. The university is still working out whether any personal, research or academic information was in the stolen data. It has said it will notify affected people once the forensic review is finished.
What Happened
UIC and College of Medicine IT staff found "unauthorized activity within portions of the College of Medicine network," according to the university's community letter. The letter was signed by Interim Executive Dean Dr. Enrico Benedetti, CIO Matt Riley and Chief Information Security and Privacy Officer Shefali Mookencherry. UIC says it started its incident response protocols, brought in outside cybersecurity experts, and contained the activity.
Sources give different dates for the disclosure. The letter on UIC's news site is dated October 2, 2026, but the site lists it as published October 5. The Record also reported the confirmation on October 5, based on a university spokesperson's statement. Daily Security Review says UIC announced the incident on October 6. Based on the letter and The Record, UIC appears to have disclosed the attack between October 2 and October 5. UIC has not said when the intrusion began, how long attackers were inside, or when it was first detected.
What the university has said about the impact:
- Disruption: Some College of Medicine systems were temporarily unavailable. UIC says all affected systems have been restored. DysruptionHub reports they were back by Monday. UIC has not named the affected systems or said how long they were down.
- Containment: The main UIC network was not affected, and UI Health patient care delivery was not affected.
- Response: UIC reported the attack to law enforcement, worked with agencies throughout recovery, and says it has added security controls.
UIC is Chicago's largest university, with more than 35,000 students across 16 colleges. About 1,300 of them are in the College of Medicine (The Record).
What Was Taken
UIC confirms that "unauthorized actors obtained some data located on College of Medicine servers." It has not said what kinds of records were taken or how many people are affected. The university's own wording is that experts are "combing through the data to determine if any personal, research or academic information has been compromised."
The only figure for the volume of data comes from the attackers. Booba claims 344 GB. The Record, BreachNews, Daily Security Review, ThreatTicker and Fawkes all report the same number, but every one of them traces it back to the gang's leak-site claim. No one has verified it independently, and UIC has not confirmed it.
No source says patient records were taken. BreachNews notes that UIC has not confirmed patient data was in the stolen set. TMC Insight points out that if protected health information turns up, the HIPAA Breach Notification Rule could apply, depending on which UIC entity controlled the data. Medical school servers can also hold student records covered by FERPA, research datasets that may include human-subjects data, and staff personnel files. Each of these comes with its own notification rules.
Who Is Behind It
Booba, which some sources call "Booba Project," appeared in late July 2026. The Record reports it has already claimed 49 victims. Brett Williams of SentinelOne told The Record the group looks like a rebrand of the Frag ransomware operation. He based that on the style of the leak site and the way the group handles negotiations. Encrypted files get a .booba extension, and there appear to be versions for both Windows and Linux.
Booba's victims so far are mostly companies and small local governments, including Merrimack County, New Hampshire. UIC is one of its most prominent victims to date. UIC has not said whether it received a ransom demand or whether it considered paying.
Why It Matters
Segmentation appears to have limited the damage, but not the data loss. UIC's account suggests that the boundary between the College of Medicine network, the main university network and UI Health's clinical systems kept the attack from spreading. Many academic medical centers lack that separation. For comparison, DysruptionHub notes that the February attack on the University of Mississippi Medical Center took down its electronic records system and closed clinics across the state. Still, the data was taken anyway. Quick recovery does not mean the data is safe.
Academic medicine sits between two sets of rules. A college of medicine holds research data, student records and possibly clinical material in a setting that is usually run more like a university department than a hospital. Its controls are often looser than those around the clinical side, while some of the data it holds is just as sensitive.
New groups that look like rebrands still act like experienced crews. If SentinelOne is right that Booba is a rebrand of Frag, then 49 claimed victims in about ten weeks reflects an established operation under a new name, not a new group learning as it goes. Detection that depends on recognizing a known gang's name will miss it. Behavior-based detection holds up better.
The Attack Technique
Not publicly known. UIC has not disclosed how the attackers got in, which systems were compromised, or how long they were inside (BreachNews, Daily Security Review). No source links the intrusion to a specific vulnerability, phishing campaign or stolen credentials.
What the sources do establish is a standard double-extortion pattern: data was taken first, then systems were encrypted, then the attack was announced on a leak site. Since Booba has a Linux build, defenders should assume it can hit Linux servers and virtualization hosts in research environments, not just Windows machines.
What Organizations Should Do
- Treat academic and research networks with the same care as clinical ones. Map where PHI, human-subjects research data and student records sit on college-level or departmental servers, and apply the same access controls and logging you use in the clinical environment.
- Check and test the separation between segments. UIC's containment shows that segmentation works. Confirm that departmental networks cannot reach core identity systems, EHR systems or the main campus network except through narrow, monitored paths.
- Watch for large data transfers before encryption starts. Alert on unusual outbound volume from research and file servers. A transfer of hundreds of gigabytes, which is what Booba claims here, should stand out in egress monitoring.
- Hunt for Booba and Frag behavior on both Windows and Linux. Watch for the
.boobafile extension, mass file renaming, and encryption activity on Linux hosts and hypervisors. Feed SentinelOne's and other vendors' indicators into your EDR. - Make sure backups can survive an attack. UIC's fast restoration points to working recovery. Confirm your backups are offline or immutable and that you have recently tested restoring departmental systems, not only enterprise ones.
- Prepare notification decisions in advance. Decide ahead of time which entity owns which data under HIPAA, FERPA and state breach laws, so a forensic finding leads straight to the right notification process instead of weeks of legal triage.
Sources: UIC Confirms Ransomware Attack on Medical Servers TMC Insight | University of Illinois Chicago affected by ransomware attack on med... | College of Medicine systems compromised UIC today | UIC Confirms Ransomware Attack and College Data Theft | UIC College of Medicine Hit by Booba Ransomware, 344 GB Claimed - R... | Booba ransomware gang claims 344 GB from University of Illinois Chi... | UIC medical school ransomware disrupts systems | UIC ransomware attack hits College of Medicine systems