Ransomware Gang Booba Steals 344 GB from University of Illinois Chicago College of Medicine
A ransomware group called Booba breached the University of Illinois Chicago’s College of Medicine, encrypting systems and exfiltrating 344 GB of data. The incident highlights the need for auditable incident‑response controls and continuous monitoring to satisfy multiple compliance frameworks.
ADTP Breach Watch· October 5, 2026· The Record
SeverityHigh
Type🎓 Ransomware
ConfidenceHigh
ReportedOct 5, 2026
Education & ResearchHigher‑education institutions with medical or research programsOrganizations storing sensitive academic or health‑related dataMalware
What happened
Booba ransomware encrypted files on the College of Medicine’s servers and stole roughly 344 GB of data, causing temporary loss of access to several college systems. The university restored the affected systems, reported the incident to law enforcement, and began notifying potentially impacted individuals.
Why it matters for trust and compliance
The event underscores the importance of a continuously monitored incident‑response program that can produce defensible evidence for auditors and regulators.
Provides a concrete example of why continuous control monitoring and evidence collection are vital for audit readiness.
Demonstrates how mapping ransomware response to control objectives supports multi‑framework compliance.
Who is affected
Higher‑education institutions with medical or research programsOrganizations storing sensitive academic or health‑related data
Recommended actions
Validate and test ransomware‑specific incident‑response playbooks.
Preserve logs, backups, and forensic data to build an audit‑ready evidence trail.
Ensure backups are frequent, immutable, and regularly restored in tests.
Map post‑incident findings to the relevant control objectives in your compliance framework.
Get the Breach Digest
The incidents that matter for your vendors and your data, analysed for practitioners, in one email.