VYPR
breachPublished Oct 5, 2026· 1 source

Ransomware Group 'Booba' Hits University of Illinois Chicago Medical School

The University of Illinois Chicago's College of Medicine has been targeted by a ransomware attack, with threat actors claiming to have exfiltrated significant amounts of data.

The University of Illinois Chicago (UIC) College of Medicine has fallen victim to a ransomware attack, leading to temporary system outages and the exfiltration of data. A university spokesperson confirmed that threat actors gained access to some of the college's servers, compromising information.

An investigation is currently underway to determine the exact nature and scope of the stolen data, specifically whether any personal, research, or academic information was affected. While some College of Medicine systems experienced temporary unavailability, the university stated that all affected systems have since been restored. Crucially, the main university network remained unaffected, and patient care delivery at UI Health was not impacted.

The incident has been reported to law enforcement agencies, and the recovery process has been coordinated with relevant authorities. UIC has committed to notifying any individuals whose information may have been compromised during the attack.

The ransomware group claiming responsibility for the attack is known as 'Booba.' This group emerged at the end of July and has already claimed responsibility for 49 attacks. Booba reportedly stated that they exfiltrated 344 gigabytes of data from UIC's servers.

Security researchers at SentinelOne suggest that Booba may be a rebrand of the 'Frag' ransomware group, citing similarities in their leak site's style and negotiation tactics. Encrypted files are typically renamed with the '.booba' extension, and the group appears to have developed variants capable of targeting both Linux and Windows operating systems.

Booba has been active in targeting various organizations, including several companies and small county governments. Notably, Merrimack County in New Hampshire recently confirmed it was the target of a cyberattack, which disrupted its dispatchers' ability to access critical criminal data from state software.

The attack on UIC highlights the persistent threat of ransomware to educational and healthcare institutions, which often hold sensitive data that can be leveraged for financial gain or disruption. The rapid emergence and activity of new ransomware groups like Booba underscore the dynamic nature of cyber threats and the need for robust cybersecurity defenses.

Synthesized by Vypr AI