Skip to content
feed: live
0dayNews
ransomware
● Breaking

Ransomware Hits UIC Medical School, Data Stolen

Ransomware struck the University of Illinois Chicago College of Medicine. Data was stolen from servers. Threat group, scope, and ransomware demand all unconfirmed.

Ransomware Hits UIC Medical School, Data Stolen
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
airgapMorgan "airgap" Reyes·Published ·1 min read

Ransomware struck the University of Illinois Chicago College of Medicine. Some data was stolen from servers. Both facts are confirmed. The Record has the initial report.

What’s confirmed

  • Ransomware attacked the UIC College of Medicine
  • Data was exfiltrated from servers
  • UIC acknowledged the incident

What’s unconfirmed

Which threat group is responsible. Whether a ransom demand was issued or paid. The volume, type, and sensitivity of the stolen data. Whether protected health information is in scope. Treat all of that as unconfirmed until UIC or law enforcement states otherwise.

Context

Medical schools are a consistent ransomware target. They hold research data, training and faculty records, and, depending on clinical affiliations, patient-linked information. UIC’s College of Medicine is affiliated with the UI Health hospital network.

Analysis: if protected health information is included in the breach, HIPAA requires notification to the Department of Health and Human Services within 60 days of discovery. That filing, if submitted, will be the clearest public measure of scope. No such filing has appeared as of this writing.

No threat group has claimed the attack. No confirmed ransom demand is public.

Watch list for this story: an HHS HIPAA breach notification, a threat group posting stolen data to a leak site, or a UIC public statement naming affected individuals.

Recent ransomware at institutions

Ransomware against public institutions and infrastructure has been active this month. A ransomware attack shut down city systems in Vicksburg, Mississippi on October 4. The Warlock group has been targeting critical infrastructure via SharePoint vulnerabilities. Earlier this week, KillSec’s RaaS operation was dismantled in a law enforcement action.

Found this useful? Share it.