University of Illinois Chicago Medicine Hit by Ransomware

The Booba gang claims data theft from college servers, though patient care at UI Health remains unaffected.

Updated on Oct. 5, 2026 in Cybersecurity

Isometric editorial illustration of a metal conduit junction box on a brick wall, representing cybersecurity and network infrastructure.
The University of Illinois Chicago College of Medicine is investigating a ransomware attack that resulted in data theft from internal research servers. AI Illustration. Upload story photo >

Live Poll

Do you trust that your local institutions are doing enough to prevent data breaches?

The University of Illinois Chicago College of Medicine confirmed a ransomware attack that restricted system access and resulted in the theft of information. While the institution reported the incident to law enforcement, the main university network and UI Health patient care services were not impacted.

Why it matters

This incident highlights the ongoing vulnerability of research institutions to targeted data exfiltration by emerging ransomware groups. The attack occurred despite the university operating 16 distinct colleges, testing the resilience of its segmented network architecture.

The attackers exfiltrated 344 gigabytes of data from College of Medicine servers and encrypted local files with the .booba extension. The malware used in the intrusion included variants specifically engineered for both Linux and Windows operating systems.

The players

University of Illinois Chicago College of Medicine

A research-focused medical school within a larger university system that manages a diverse array of academic and clinical server networks.

Booba

A ransomware collective active since July 2026 that has claimed responsibility for 49 separate cyberattacks against various targets.

The details

The intrusion targeted servers within the College of Medicine, which serves 1,300 students out of the 35,000 enrolled at the University of Illinois Chicago. Attackers utilized malicious software capable of executing on multiple operating system environments to bypass security controls and encrypt internal files. Although system access was initially limited, the university has since restored the affected infrastructure, and officials are in the process of identifying individuals whose data was compromised.

Timeline

  1. The Booba ransomware group first emerged at the end of July 2026.

  2. The gang formally claimed responsibility for the attack on the university last week.

The Tech Race

This intrusion follows the pattern of the broader 2026 Booba ransomware campaign, which has targeted 49 organizations globally since July. The attack marks another milestone in the group's aggressive expansion and operational tempo.

University personnel and students should monitor official communication channels for upcoming notifications regarding the compromise of personal data. While daily operations at UI Health and the broader university network have resumed, users should remain vigilant against follow-up phishing attempts.

The takeaway

The university is currently working to identify and notify individuals affected by the data breach. Readers should monitor the institution’s official announcements for instructions on identity protection steps as the investigation unfolds.

Further reading

For broader analysis on current network defense strategies, see our coverage in Cybersecurity.

Live Poll

Do you trust that your local institutions are doing enough to prevent data breaches?