UIC ransomware attack hits College of Medicine systems

UIC ransomware attack hits College of Medicine systems

The University of Illinois Chicago (UIC) has confirmed a ransomware attack that cut off access to some systems at its College of Medicine. The attackers also took data from the college's servers.

A university spokesperson told Recorded Future News that an investigation is underway to establish whether "any personal, research or academic information was compromised." The university has not yet said what kind of data was taken or how many people may be affected.

Systems restored, patient care unaffected

According to UIC, the attack only hit part of the institution. "As a result of this ransomware event, some College of Medicine systems were temporarily unavailable," the spokesperson said. "However, all affected systems have since been restored. The university's main network was not affected, and there was no impact on patient care delivery at UI Health."

UI Health is the university's clinical arm, which runs its hospital and patient services. The university's statement suggests the intrusion was kept away from systems that support patient care.

UIC said it reported the incident to law enforcement. It also worked with agencies throughout the recovery. The university plans to notify anyone whose information was stolen.

UIC is the largest university in Chicago. It has more than 35,000 students across 16 colleges, and about 1,300 of them study at the College of Medicine.

Booba claims 344 GB of data

A ransomware gang called Booba claimed the attack last week. The group says it stole 344 gigabytes of data. UIC has not confirmed that figure.

Booba is a newcomer. It appeared at the end of July and has already listed 49 victims. Brett Williams of SentinelOne said the group appears to be a rebrand of the Frag ransomware operation. He based that view on the style of the leak site and the way the group handles negotiations.

Files encrypted by Booba are renamed with a .booba extension. There also appear to be versions of the ransomware for both Windows and Linux systems.

Small governments on the victim list

Booba's victims so far include several companies and small county governments. One of them is Merrimack County in New Hampshire.

The county confirmed to local news outlets and to DysruptionHub, a site that tracks cyber incidents, that it had dealt with a cyberattack several weeks earlier. Officials said it has since recovered.

The incident had real effects on public safety work. Local outlet Patch reported that county dispatchers could not pull criminal data from the state's software to pass on to officers while the attack was ongoing. This is similar to other attacks on local government, such as the Vicksburg ransomware attack that recently forced a Mississippi city offline.

Questions still open

Several details are still unknown. UIC has not said how the attackers got in, when the intrusion began, or whether it received a ransom demand. It also has not said whether research data, student records or staff information were among the stolen files.

The answer matters. Medical schools hold a mix of academic records, research material and, in some cases, data linked to clinical work. UIC's notification letters, once sent, should show more clearly what was exposed.

Our Take

The UIC case follows a pattern that has become common in ransomware. Attackers steal data first and encrypt systems second, so that a quick recovery does not end the incident. UIC restored its systems, but the 344 GB that Booba claims to hold may still be used as leverage. Restoring operations is only half of the response. The other half is working out what left the network and who needs to be told.

The attack also shows that universities, and medical schools in particular, remain attractive targets. They run large, decentralised networks with many users and valuable data. The fact that UIC's main network and UI Health were not affected suggests some degree of separation between systems. That kind of segmentation is worth copying. Pressure on the wider healthcare sector is also showing up in policy, as the healthcare cybersecurity bill moving through the US Congress shows. The education sector keeps showing up in breach reports too, including the recent Frontline Education breach.

Booba's apparent link to Frag points to another familiar trend: ransomware crews rebranding to shake off attention while keeping their tools and methods. Forty-nine claimed victims in roughly two months suggests the group is moving fast. It is worth watching whether Booba keeps going after small public bodies such as county governments, where an outage can quickly affect emergency services. It is also worth watching whether researchers find more technical links to Frag. For now, defenders should treat the .booba extension and the group's Windows and Linux variants as signs worth tracking.