The University of Illinois Chicago has confirmed that ransomware attackers stole data from systems belonging to its College of Medicine, while a newly active ransomware operation called Booba Project claims to have taken 344 GB.
The attack temporarily made some College of Medicine systems unavailable, according to statements provided by UIC. The university said the affected systems have since been restored and that its main university network was not impacted.
Despite the attack targeting the medical school, UIC said there was no disruption to patient care at UI Health.
Investigators are now working to determine whether the information stolen from College of Medicine servers includes personal, research or academic data. UIC said it will notify individuals if the investigation determines their information was compromised.
Attackers stole data from College of Medicine servers
UIC has confirmed both the ransomware incident and data theft, distinguishing the attack from ransomware listings where the victim organization has not acknowledged an intrusion.
The university reported the incident to law enforcement and said it coordinated with agencies during the recovery process. UIC has not publicly disclosed the initial access method, the specific systems compromised, when attackers first gained access or how long they remained inside the environment.
The scope of the stolen information also remains under investigation. While UIC acknowledged that attackers obtained information held on College of Medicine servers, it has not confirmed that patient records were among the stolen data.
That distinction is significant because UIC operates both academic and healthcare infrastructure. The university says it has more than 35,000 students across 16 colleges, as well as a hospital and health sciences system.
The College of Medicine’s role includes medical education and research, creating the possibility that compromised servers could contain several different categories of information. UIC is specifically investigating whether personal, research or academic information was affected.
Booba Project Claims 344 GB of Stolen Data
Booba Project has claimed responsibility for the ransomware attack and alleges it stole 344 GB of information from UIC.
UIC has not attributed the intrusion to Booba Project, and the ransomware operation’s claimed 344 GB data volume has not been independently verified.
Public ransomware tracking indicates that Booba Project is a relatively new operation that emerged in 2026 and has already listed victims across multiple sectors, including education, healthcare and government organizations.
Security researchers have also reported similarities between Booba Project and the earlier Frag ransomware operation, including aspects of its leak infrastructure and negotiation process. Reports indicate the ransomware can encrypt Windows and Linux systems and append a .booba extension to encrypted files.
Those similarities do not establish who operates the group or whether Booba Project represents a direct continuation of Frag.
Illinois Colleges Have Faced Other Extortion Claims
The UIC incident follows several cyberattacks and extortion campaigns affecting educational institutions, including another Illinois college targeted earlier this year.
In June, ShinyHunters listed Illinois Central College among several U.S. educational institutions it claimed to have compromised. BreachNews reported that ShinyHunters targeted Illinois Central College alongside 3 other U.S. colleges as part of an education-sector extortion campaign.
ShinyHunters claimed to have obtained approximately 28 GB containing 122,000 files from Illinois Central College, with the purported material spanning systems related to human resources, payroll, curriculum administration and PeopleSoft Campus Solutions. The claimed scope was not independently confirmed.
The UIC and Illinois Central College incidents are not known to be connected. Different threat actors claimed the attacks, and there is currently no evidence indicating a shared intrusion method or infrastructure. Their geographic and sector overlap nevertheless highlights the continuing exposure of Illinois higher education institutions to data theft and extortion operations.
Education organizations have also faced broader campaigns involving enterprise software used across university environments. BreachNews previously reported on ShinyHunters-linked exploitation of an Oracle PeopleSoft zero-day targeting universities, although there is no indication that the PeopleSoft vulnerability played a role in the UIC ransomware attack.
Medical Schools Present a Mixed Data Target
Academic medical institutions can present particularly valuable targets because their systems may combine university administration, research operations and healthcare-related functions.
In UIC’s case, the university has specifically said patient care at UI Health was unaffected. There is also no public confirmation that electronic health records or other patient information were accessed.
The investigation into personal, research and academic information will therefore be important in determining whether the incident develops primarily into an education-sector data breach, a research data compromise or an exposure involving individuals connected to the College of Medicine.
The attack also follows several significant cybersecurity incidents involving healthcare organizations covered by BreachNews. In September, ShinyHunters claimed a breach involving Fresenius Medical Care, while earlier incidents have affected healthcare platforms and organizations holding large volumes of patient information.
Investigation Continues After Systems Restored
UIC’s restoration of the affected College of Medicine systems limits the immediate operational impact, but the confirmed theft of information leaves the university with a potentially longer investigation into what attackers accessed and removed.
The university has not disclosed whether files were encrypted across the compromised servers, whether a ransom was demanded or whether it communicated with the attackers.
It also remains unclear how Booba Project allegedly gained access to the College of Medicine environment. No vulnerability, compromised account, phishing attack or other initial access vector has been publicly identified.
UIC said it intends to notify affected individuals if its investigation determines their information was stolen. The university has confirmed that the main UIC network remained unaffected and that patient care continued throughout the incident.










