The University of Illinois Chicago discovered a ransomware attack against its College of Medicine that temporarily disrupted some systems and involved information theft. UIC said all affected systems have been restored, while its main university network and patient care delivery at UI Health were unaffected. An investigation is continuing to determine whether personal, research, or academic information was compromised.
The Booba ransomware gang claimed responsibility and alleged it stole 344 gigabytes of data; that volume has not been independently confirmed. SentinelOne researcher Brett Williams assessed that Booba appears to be a rebrand of Frag ransomware, citing similarities in its leak site and negotiation process. Booba has also claimed an attack against Merrimack County, New Hampshire, where a confirmed cyberattack disrupted dispatchers’ access to state criminal data. For UIC, system restoration leaves the scope and sensitivity of the stolen information as the principal unresolved risk.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
SentinelOne researcher Brett Williams assessed that Booba appears to be a rebrand of Frag ransomware, citing similarities in leak-site styling and negotiation flow.
UIC said all affected systems had been restored, its main network and UI Health patient care were unaffected, and it had reported the incident to law enforcement. The university was investigating whether personal, research, or academic information was compromised and planned to notify affected individuals.
The Booba ransomware gang claimed responsibility for the UIC attack and alleged that it stole 344 gigabytes of data.
The University of Illinois Chicago discovered a ransomware attack that temporarily made some College of Medicine systems unavailable. A university spokesperson confirmed that attackers stole information from the college's servers.
Merrimack County confirmed to local news outlets and DysruptionHub that it had experienced a cyberattack several weeks earlier and had since recovered.
Merrimack County, New Hampshire, experienced a cyberattack that prevented dispatchers from accessing criminal data through state software to share with officers. Booba claimed the county as a victim.
The report stated that Booba emerged at the end of July and subsequently claimed 49 attacks. The supplied content does not specify the year of its emergence.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcescworld.com
Open sourcedysruptionhub.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.