University of Illinois Chicago Medicine Hit by Ransomware
The Booba gang claims data theft from college servers, though patient care at UI Health remains unaffected.
Updated on Oct. 5, 2026 in Cybersecurity

Live Poll
Do you trust that your local institutions are doing enough to prevent data breaches?
The University of Illinois Chicago College of Medicine confirmed a ransomware attack that restricted system access and resulted in the theft of information. While the institution reported the incident to law enforcement, the main university network and UI Health patient care services were not impacted.
Why it matters
This incident highlights the ongoing vulnerability of research institutions to targeted data exfiltration by emerging ransomware groups. The attack occurred despite the university operating 16 distinct colleges, testing the resilience of its segmented network architecture.
The attackers exfiltrated 344 gigabytes of data from College of Medicine servers and encrypted local files with the .booba extension. The malware used in the intrusion included variants specifically engineered for both Linux and Windows operating systems.
The players
University of Illinois Chicago College of Medicine
A research-focused medical school within a larger university system that manages a diverse array of academic and clinical server networks.
Booba
A ransomware collective active since July 2026 that has claimed responsibility for 49 separate cyberattacks against various targets.
The details
The intrusion targeted servers within the College of Medicine, which serves 1,300 students out of the 35,000 enrolled at the University of Illinois Chicago. Attackers utilized malicious software capable of executing on multiple operating system environments to bypass security controls and encrypt internal files. Although system access was initially limited, the university has since restored the affected infrastructure, and officials are in the process of identifying individuals whose data was compromised.
Timeline
The Booba ransomware group first emerged at the end of July 2026.
The gang formally claimed responsibility for the attack on the university last week.
The Tech Race
This intrusion follows the pattern of the broader 2026 Booba ransomware campaign, which has targeted 49 organizations globally since July. The attack marks another milestone in the group's aggressive expansion and operational tempo.
University personnel and students should monitor official communication channels for upcoming notifications regarding the compromise of personal data. While daily operations at UI Health and the broader university network have resumed, users should remain vigilant against follow-up phishing attempts.
The takeaway
The university is currently working to identify and notify individuals affected by the data breach. Readers should monitor the institution’s official announcements for instructions on identity protection steps as the investigation unfolds.
Further reading
For broader analysis on current network defense strategies, see our coverage in Cybersecurity.
Live Poll
Do you trust that your local institutions are doing enough to prevent data breaches?






