A new ransomware has highlighted the risks facing educational and research institutions, as the University of Illinois Chicago (UIC) confirmed an incident affecting systems at its School of Medicine. The attack temporarily restricted access to some infrastructure, while the perpetrators also appear to have gained access to and stolen data stored on the school’s servers.

The university has launched an internal investigation to determine exactly what data was affected and whether it included personal information, research materials, or academic data. This process is particularly important, as a breach in a Medical School environment can involve highly sensitive information.
The systems are back in operation
According to a UIC spokesperson, some systems at the School of Medicine were temporarily down following the incident. However, restoration has now been completed and the affected systems have returned to normal operation.
See also: CPR Register Denmark: Data leak of 8.8 million people
It is also important that, according to the university, the attack did not extend to the UIC main network. At the same time, there was no interruption in the provision of medical care through UI Health. This parameter significantly limits the immediate operational impact of the attack, but does not eliminate the potential consequences of data theft.
The incident was reported to the relevant authorities, while the investigation and remediation process was carried out in cooperation with the relevant services. The university has also stated that it will inform individuals who may have been affected if it is confirmed that their personal information was stolen.
University of Illinois Chicago: Booba ransomware group claims responsibility
The Booba ransomware group , which first emerged in late July and has already been linked to dozens of incidents, claimed responsibility for the attack. The group claims to have managed to remove approximately 344 GB of data from UIC's systems.
This claim comes from the perpetrators themselves and has not been fully confirmed by the university. This is important, as ransomware groups often publish exaggerated or unverified claims in order to increase pressure on victims during negotiations.

Possible rebrand of Frag ransomware
Booba's activity has already attracted the attention of cybersecurity researchers. Brett Williams believes that the group may be essentially a rebranding of the Frag ransomware.
See also: Wikimedia Foundation reports action by OpenAI agents
The estimate is based on similarities found on the website where stolen data is posted and the way in which negotiations with victims are conducted. The ransomware uses the .booba for encrypted files, and variants targeting both systems Windows and Linux.
This specific capability expands the team's potential scope of action, as modern organizational infrastructures are based on different operating environments, servers and virtualized systems.
From universities to local authorities
Booba does not appear to be limiting its activities to academia. The group has reported attacks against businesses as well as local government organizations, indicating a broader pattern of targeting.
Among the victims linked to its activity is Merrimack in New Hampshire. The local authority confirmed that it suffered a cyberattack several weeks ago and that it was subsequently able to restore its operations.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
However, the consequences were not limited to technical glitches. According to reports, employees at the county operations center temporarily lost access to criminal record data through state software, making it difficult for them to provide specific information to police officers.

The risk to sensitive data
The UIC attack highlights a critical feature of modern ransomware campaigns: file encryption is now only part of the threat. Attackers often first seek to gain access to valuable information and then use its potential disclosure as leverage.
See also: DTU: Breach in the DTUBasen system may affect up to 200,000 users
For a university with more than 35,000 students and multiple faculties, the volume of data managed by the infrastructure is enormous. In the case of a Medical School, the potential content may include research files, academic information , and other data that requires increased protection.
UIC says systems have been restored, but the full picture of the attack will only be known once the investigation is complete. Until then, the case is yet another reminder that immediate system isolation, secure backups, and constant network monitoring remain critical defenses against ransomware.
