Booba Gang Claimed Ransomware Attack on UIC Medicine

The ransomware group compromised college servers, though officials report that patient care services remained unaffected.

Updated on Oct. 5, 2026 in Cybersecurity

Bold flat-color editorial illustration of a stylized server rack and digital data lines, representing institutional cybersecurity infrastructure.
The University of Illinois Chicago College of Medicine is investigating a ransomware attack that compromised internal systems, though patient health services remain unaffected. AI Illustration. Upload story photo >

Live Poll

Do you trust that your local institutions are doing enough to prevent data breaches?

The University of Illinois Chicago College of Medicine recently experienced a ransomware attack involving the Booba hacking group. While college servers were compromised, the university main network and patient care delivery at UI Health were not impacted.

Why it matters

The breach highlights the increasing vulnerability of academic medical institutions to emerging cybercriminal syndicates. By compromising internal systems, the attackers gained access to significant amounts of sensitive data before the college restored its systems.

The Booba ransomware gang, which emerged in late July 2026, claimed to have exfiltrated 344 gigabytes of data from the college. The University of Illinois Chicago maintains 16 colleges and serves a total population of 35,000 students.

The players

University of Illinois Chicago College of Medicine

This institution is one of 16 colleges within the University of Illinois Chicago system and serves approximately 1,300 medical students.

Booba

This is a ransomware gang that has claimed responsibility for 49 separate cyberattacks since its emergence in July 2026.

UI Health

This organization oversees clinical operations and patient care for the university and remained unaffected during the recent cyber incident.

The details

The attackers used malware capable of targeting both Linux and Windows operating systems, renaming encrypted files with the .booba extension. The university has already reported the security incident to law enforcement and is preparing to notify individuals whose personal information was accessed.

Timeline

  1. The Booba ransomware group emerged at the end of July 2026.

  2. The group officially claimed responsibility for the attack on the college last week.

The Tech Race

The attack represents a growing trend of specialized ransomware groups targeting academic medical institutions to exfiltrate large volumes of sensitive research and personal data. This incident mirrors the tactics seen in other recent attacks attributed to the Booba collective, highlighting the ongoing arms race between university security protocols and evolving malware variants.

Students and faculty should remain alert for potential phishing attempts or notifications regarding the theft of their personal information. While campus systems have been restored, the university is currently managing the notification process for all affected parties.

The takeaway

Institutions must continue to harden their digital perimeters as gangs like Booba increasingly target university infrastructure for data theft. Readers should prioritize enabling multi-factor authentication on all academic accounts to protect against similar unauthorized access.

Further reading

For more information on current digital threats, see the Cybersecurity section.

Source note: This article includes information reported by Therecord.

Live Poll

Do you trust that your local institutions are doing enough to prevent data breaches?