Booba ransomware gang claims 344 GB from University of Illinois Chicago medical school

UIC says College of Medicine systems were briefly disrupted and data was stolen in a ransomware attack. The Booba gang, which researchers link to a Frag rebrand, claimed the intrusion.

Booba ransomware gang claims 344 GB from University of Illinois Chicago medical school

At a glance

  • The Record reports UIC confirmed a ransomware attack on its College of Medicine that temporarily knocked out some systems and involved data theft.
  • The Booba ransomware gang claimed the intrusion and says it took 344 gigabytes of data.
  • SentinelOne's Brett Williams assesses Booba, which surfaced in late July 2026, as a rebrand of the Frag ransomware operation.
  • UIC says its main network and UI Health patient care were unaffected and all affected systems have been restored.

The University of Illinois Chicago has confirmed that a ransomware attack hit its College of Medicine, temporarily disrupting some systems and resulting in the theft of data, The Record reported on 5 October 2026. The intrusion was claimed by a ransomware gang the week before the university's confirmation, and the group says it carried off 344 gigabytes of data.

What happened

According to The Record's reporting, the incident was limited to College of Medicine systems, which were temporarily unavailable. A university spokesperson said "all affected systems have since been restored. The university's main network was not affected, and there was no impact on patient care delivery at UI Health." UIC said it reported the incident to law enforcement and that it plans to notify affected individuals.

The university is still investigating whether "any personal, research or academic information was compromised," so the scope of the stolen data has not been established. The 344 gigabyte figure comes from the attackers' own claim and has not been independently verified.

Who is behind it

The claim was posted by Booba, a ransomware operation that emerged in late July 2026. SentinelOne researcher Brett Williams told The Record the group appears to be "a rebrand of the Frag ransomware based on the leak site's style and negotiation flow" — the kind of assessment that rests on operational tradecraft rather than on code overlap, and which the researcher framed as an appearance rather than a confirmed identity.

Rebrands are routine in this market: retiring a name that has attracted law enforcement attention while keeping the same affiliates, tooling and leak infrastructure is cheaper than rebuilding an operation. For defenders, the practical consequence is that a brand-new leak site name does not imply a brand-new adversary or new techniques.

Who is affected

UIC serves more than 35,000 students across 16 colleges, with roughly 1,300 of them enrolled at the College of Medicine. Medical schools are a particularly awkward target because their systems can hold a mix of student records, employee data, clinical training material and research data — categories that carry different notification duties and different value to an extortion crew. The university's statement separating the College of Medicine from UI Health matters here: it keeps the incident outside the operational clinical environment, at least as currently understood.

What to do

Universities and research institutions should treat faculty-level IT estates as part of the attack surface rather than as isolated units, since a college network that sits adjacent to a central network is exactly the foothold extortion groups look for. Because this was a data theft incident as well as an encryption event, affected individuals should expect notification letters and watch for targeted phishing that references the university by name. Organisations tracking Booba should map it against existing Frag indicators and negotiation patterns rather than starting from scratch.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.