UIC College of Medicine Hit by Booba Ransomware, 344 GB Claimed

The University of Illinois Chicago says data was taken from College of Medicine servers; the Booba ransomware gang claims 344 GB stolen from the school.
Table of Contents
    Add a header to begin generating the table of contents

    The University of Illinois Chicago (UIC) said on October 6 that unauthorized actors obtained data from servers at its College of Medicine and that some systems were temporarily unavailable. The Booba ransomware gang has claimed the attack and says it stole 344 GB of data from the school.

    What UIC Has Disclosed About the College of Medicine Attack

    UIC announced the incident on October 6. In its statement, the university said unauthorized actors had obtained data from College of Medicine servers and that some systems were temporarily unavailable as a result. The university did not disclose the date on which the attack took place, so the length of time between the intrusion and the announcement is not known.

    The disclosure confirms data theft from the servers but does not describe what kinds of records were on them. UIC has not said how many people are affected.

    UIC Says the Main Network and UI Health Patient Care Were Not Affected

    UIC stated that its main university network and UI Health patient care were not affected. The impact the university describes is confined to the College of Medicine. UI Health is the university’s patient care operation, and the statement separates it from the servers that were compromised.

    Law Enforcement Notified and Forensic Review Under Way

    The university reported the incident to law enforcement, and a forensic review is ongoing. UIC said it has added security controls in response and that affected individuals will be notified. The notifications will follow the review, which has not been given a completion date.

    Booba Claims the Attack and 344 GB of Stolen Data

    The Booba ransomware gang claimed responsibility for the attack and said it holds 344 GB of stolen data. UIC has not confirmed that figure. The claim and the university’s statement agree on the central point that data left the College of Medicine servers, but the university has not verified the volume or the contents.

    If the claimed volume is accurate, the material could include personal, research or academic data. The reporting available does not say which of these categories the stolen files contain, and the university has not specified what the exposed information consists of.

    Who Is Behind Booba Ransomware

    Booba is a new name in ransomware. The group emerged in late July 2026 and has since claimed 49 attacks. Its encryptor appends the .booba extension to affected files, and the group operates both Windows and Linux variants of its malware.

    SentinelOne’s Brett Williams Links Booba to Frag Ransomware

    Brett Williams of SentinelOne assesses Booba as a likely rebrand of Frag ransomware. Under that assessment, Booba is not a new crew but a continuation of an earlier operation under a new name. The assessment is described as likely, not confirmed.

    Booba’s 49 Claimed Attacks in Roughly Two Months

    Booba’s first public activity dates to late July, and its tally had reached 49 claimed attacks by the time of the UIC announcement. The University of Illinois Chicago College of Medicine joins that list as an education and healthcare-adjacent victim.

    Impact on the College of Medicine

    The immediate effect of the attack was that some College of Medicine systems were temporarily unavailable. The university has not said which systems were affected, how long they were offline, or whether they have all been restored.

    The longer-term effect depends on what the stolen data contains. The Booba claim of 344 GB points to a large volume of material, and UIC’s statement that affected individuals will be notified indicates the university expects personal information to be involved. Until the forensic review concludes, the number of people who will receive notices is not known.

    The attack also does not appear to have reached the systems that support patient care. UIC said UI Health patient care was unaffected, which separates this incident from ransomware attacks that have disrupted clinical operations at other healthcare organizations.

    Related Posts