Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
The University of Illinois Chicago's College of Medicine confirmed on Oct. 5, 2026, that it discovered a ransomware attack that limited access to some of the university's computer systems. The criminal group Booba claimed responsibility with a post dated Oct. 2, asserting it stole 344 GB of data — a figure not independently verified. The university has restored systems and denied impact on the main network and patient care, but has not issued a technical advisory with indicators of compromise or an attack vector.
- The UIC College of Medicine suffered a ransomware attack with data theft from the institute's servers; the investigation into the nature of the compromised data is ongoing.
- The Booba group, which emerged in late July 2026 with 49 claimed attacks, published its claim against UIC on Oct. 2, 2026.
- All affected systems have been restored, the main university network was not affected, and patient care delivery at UI Health was not interrupted.
- The dossier contains no details on the initial access vector, specific variants used, or indicators of compromise released by the institution.
The College of Medicine Attack: A Three-Day Timeline
The incident surfaced publicly on Oct. 5, 2026, when a University of Illinois Chicago spokesperson responded to inquiries from The Record. The official statement establishes that the university "recently discovered a ransomware attack that limited access to some College of Medicine systems." The wording leaves open the gap between the intrusion date, discovery date, and claim date: Booba's claim on Ransomware.live is dated Oct. 2, three days before the institutional confirmation.
According to the same source, "the hackers managed to steal some information contained on the college's servers" and an investigation is underway to determine whether "personal, research, or academic information was compromised." The specific nature of the exposed data has not been disclosed. The university stated the incident was reported to law enforcement and that recovery was coordinated with agencies during the restoration process, without naming the entities involved.
The spokesperson clarified that "some College of Medicine systems were temporarily unavailable," but that "all affected systems have since been restored." The university's main network "was not affected" and "there was no impact on the delivery of patient care at UI Health." UIC, with more than 35,000 students across 16 colleges, also said it will notify anyone whose information was stolen, implying the involvement of personal data.
"The group appears to be a rebrand of the Frag ransomware based on the leak site style and negotiation flow"
— Brett Williams, SentinelOne (via The Record)
Booba: An Emerging Group with Double-Extortion Tactics
Booba emerged as a ransomware affiliate in late July 2026. According to The Record, the group claimed 49 attacks in the short window since its appearance. Encrypted files are renamed with the .booba extension and, according to the same source, "there are variants for Linux and for Windows." The cross-platform capability indicates operational maturity that expands the attack surface beyond traditional Windows endpoints.
Analysis by Brett Williams of SentinelOne, cited by The Record, links Booba to a possible rebrand of the Frag ransomware group. The assessment rests on two externally observable elements: the leak site's visual style and the negotiation flow with victims. Williams' phrasing is cautious — "appears to be" — and the dossier contains no forensic technical evidence confirming infrastructural continuity between the two groups. The finding remains indicative, not proven.
The claim of 344 GB of data stolen from UIC comes exclusively from the group's claim on Ransomware.live, a platform that aggregates ransomware claims with an explicit legal disclaimer about non-verification of published content and non-accessibility to the actual stolen data. No independent source has confirmed this figure.
The Technical Silence: What UIC Isn't Saying
The absence of a technical advisory from the University of Illinois Chicago is the most significant datum for security practitioners. The institutional spokesperson did not provide: the initial access vector used by the attackers; any exploited CVE vulnerabilities; the specific Booba variant employed (Windows or Linux); indicators of compromise (IOCs) useful for verifying intrusion in other environments; or the presence or amount of any ransom demand.
This communication profile is not anomalous in the U.S. academic sector, where institutions tend to balance transparency with legal, regulatory compliance, and reputational concerns. However, the decision not to publish technical details deprives the community of the ability to independently verify whether the same TTPs (tactics, techniques, procedures) have been reused elsewhere, or whether the Booba group is pursuing similar targets with identical approaches.
The dossier contains no evidence linking the four CVEs cited in the Tech Jack Solutions briefing — CVE-2026-104286 (FortiMail), CVE-2026-65660 (SharePoint), CVE-2026-88779 and CVE-2026-88771 (NetScaler) — to the specific UIC incident. The presence of these vulnerabilities in the weekly briefing is mere general context and does not constitute an indication of use in the College of Medicine attack.
Why This Matters
The dossier does not specify the initial access method, the ransomware variant employed, or any preventive measures the university had activated before the incident. The source does not document specific remedial measures beyond system restoration and planned notification. No publicly released indicators of compromise from the institution emerge from the cited measure.
The brief does not list additional entities involved beyond the College of Medicine, nor does it detail the Booba operators' profile beyond SentinelOne's external analysis. The motive is presumably financial, but the dossier does not report statements from the group on the matter. It is also not known whether UIC paid or refused any ransom.
The case's importance lies in the tension between operational resilience and informational opacity: the university restored services and protected the main network, but the lack of technical data on the attack vector prevents other medical-academic institutions from verifying their exposure to similar TTPs.
The Medical-Academic Target in Ransomware Crosshairs
The UIC attack fits an established pattern. The College of Medicine, with roughly 1,300 students, represents a dual-value target: it hosts potentially commercializable medical research data and personal data of students, researchers, and patients subject to regulatory notification. The combination of encryption and exfiltration — Booba's standard double extortion — exploits precisely this overlap of informational value and reputational cost.
The choice not to impact UI Health and to isolate the main network suggests pre-existing architectural segmentation, but the dossier does not document the details of this separation. The fact that patients suffered no care interruptions does not imply clinical data was preserved: the ongoing investigation into the nature of the stolen data explicitly includes "personal, research, or academic information," without excluding protected categories.
The speed with which Booba claimed the attack — claim published Oct. 2, before official confirmation — signals aggressive negotiating pressure, typical of groups that lean on publishing stolen data as their primary lever. The lack of independent verification of the claimed 344 GB leaves the claim's credibility open, but does not reduce the institution's legal exposure.
Information is based on the cited advisory and current as of publication.
Sources
- https://therecord.media/ransomware-university-illinois-chicago
- https://ransomware.live/id/VW5pdmVyc2l0eSBvZiBJbGxpbm9pcyBDaGljYWdvQEJvb2JhIFByb2plY3Q=
- https://it.uic.edu/about/communications/all-news/?hl=en
- https://techjacksolutions.com/security/briefing/weekly-security-intelligence-briefing-week-of-2026-10-05/
- https://nvd.nist.gov/vuln/detail/CVE-2026-104286
- https://nvd.nist.gov/vuln/detail/CVE-2026-65660
- https://nvd.nist.gov/vuln/detail/CVE-2026-88779
- https://nvd.nist.gov/vuln/detail/CVE-2026-88771
Information is based on the cited source and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.