Ransomware Hits UIC Medical School, Data Stolen
Ransomware struck the University of Illinois Chicago College of Medicine. Data was stolen from servers. Threat group, scope, and ransomware demand all unconfirmed.

Ransomware struck the University of Illinois Chicago College of Medicine. Some data was stolen from servers. Both facts are confirmed. The Record has the initial report.
What’s confirmed
- Ransomware attacked the UIC College of Medicine
- Data was exfiltrated from servers
- UIC acknowledged the incident
What’s unconfirmed
Which threat group is responsible. Whether a ransom demand was issued or paid. The volume, type, and sensitivity of the stolen data. Whether protected health information is in scope. Treat all of that as unconfirmed until UIC or law enforcement states otherwise.
Context
Medical schools are a consistent ransomware target. They hold research data, training and faculty records, and, depending on clinical affiliations, patient-linked information. UIC’s College of Medicine is affiliated with the UI Health hospital network.
Analysis: if protected health information is included in the breach, HIPAA requires notification to the Department of Health and Human Services within 60 days of discovery. That filing, if submitted, will be the clearest public measure of scope. No such filing has appeared as of this writing.
No threat group has claimed the attack. No confirmed ransom demand is public.
Watch list for this story: an HHS HIPAA breach notification, a threat group posting stolen data to a leak site, or a UIC public statement naming affected individuals.
Recent ransomware at institutions
Ransomware against public institutions and infrastructure has been active this month. A ransomware attack shut down city systems in Vicksburg, Mississippi on October 4. The Warlock group has been targeting critical infrastructure via SharePoint vulnerabilities. Earlier this week, KillSec’s RaaS operation was dismantled in a law enforcement action.
Found this useful? Share it.


