Booba ransomware hits UIC College of Medicine, 344GB claimed
The University of Illinois Chicago College of Medicine was hit by ransomware; the Booba group claims 344GB stolen. UIC says patient care and the main network were unaffected and systems are restored.
The University of Illinois Chicago (UIC) College of Medicine was hit by a ransomware attack that took some of its systems offline, the university confirmed. The Booba group has claimed the intrusion and says it stole 344GB of data. UIC says its main university network and UI Health patient care were not affected, and that the downed College of Medicine systems have been restored. There is no vendor advisory to point at here — the sourcing is UIC's own statement and the attackers' leak-site claim, relayed in reporting at The Record; treat the 344GB figure as the group's claim, not a verified count.
What's affected
The impact was scoped to the College of Medicine: temporary system outages, now resolved. UIC says the broader university network and, critically, UI Health's clinical operations were not disrupted — no patient-care impact reported. The university says it is still investigating whether "personal, research, or academic information" was accessed, and plans to notify anyone whose data turns out to have been exposed.
The actor
The attack is claimed by Booba, which SentinelOne researcher Brett Williams has described as a rebrand of the Frag ransomware — it appends a .booba extension to encrypted files. Attribution rests on the group's own leak-site post plus that tooling overlap; no indictment or law-enforcement filing names anyone, so this stays "Booba claims it," not a confirmed operator identity.
Action checklist
- UIC College of Medicine affiliates — faculty, students, researchers, clinical staff — should watch for breach-notification correspondence and treat any "UIC password reset" message skeptically until the official notice lands.
- Rotate credentials tied to College of Medicine systems, especially any reused elsewhere, given the claimed 344GB haul.
- Defenders generally: hunt for the
.boobafile extension and Frag-family TTPs if you run health-sector or research infrastructure. Pull current Frag/Booba indicators from your threat-intel feed rather than relying on the claim counts in press coverage.
Context
Academic medical centers sit at an awkward intersection — research data, student PII, and clinical systems under one roof, often on flatter networks than a standalone hospital runs. UIC's containment claim, that the medical school was hit but UI Health patient care was not, is the outcome network segmentation is supposed to buy. Whether the segmentation held by design or by luck is the question the post-incident review should answer, and the one peer institutions should be asking of their own environments now.