High Unverified

University of Illinois Chicago Ransomware Claim by Booba Project (Oct 2026)

By Yazoul AI · automated

Unverified dark web claim. This report is based on a post observed on a dark web forum. Yazoul Security has not independently verified the authenticity of this claim.

Claim Summary

The University of Illinois Chicago (UIC) has been listed on a leak site operated by a ransomware group calling itself “Booba Project.” According to the threat actor, the alleged attack occurred on October 2, 2026, and purportedly involved the exfiltration of 344 GB of data. The group claims the stolen material falls under the category of “Higher Education Stolen data.”

This claim has NOT been independently verified by Yazoul Security or any third party. UIC has not publicly confirmed the incident at the time of writing. The listing should be treated as an unverified assertion by a criminal actor with a vested interest in pressuring the victim.

Threat Actor Profile

Booba Project is a ransomware operation with limited public documentation. At the time of this report, no established victim count, toolset, or operational history has been independently catalogued. No public research references, YARA rules, or detection signatures are currently available for this group.

Because the group’s track record is essentially undocumented, its credibility cannot be assessed with confidence. Ransomware groups frequently rebrand, exaggerate data volumes, or recycle prior leaks to inflate their reputation. The absence of known tooling and prior victims means defenders should not assume the group possesses sophisticated capabilities - nor should they assume the claim is fabricated. Both possibilities remain open.

Organizations should monitor for common ransomware tradecraft regardless of group attribution, including initial access via phishing, exploitation of edge devices, and credential abuse. Standard detection coverage for these vectors remains advisable.

Alleged Data Exposure

The group claims to hold 344 GB of data allegedly taken from UIC systems. No data samples, file listings, or proof-of-exfiltration artifacts have been reviewed by Yazoul Security. The stated volume is significant but not unusual for a large public university, which typically maintains extensive records across research, enrollment, and administrative systems.

No personally identifiable information, credentials, or download references are included in this report, in line with our editorial policy. The mere assertion of a data volume does not confirm that any data was actually taken.

Potential Impact

If the claim is accurate, a higher education institution of UIC’s size could face exposure across student records, research data, and administrative files. Potential consequences include regulatory scrutiny under FERPA and state privacy laws, notification obligations, and reputational harm.

However, ransomware actors routinely overstate data volumes to increase leverage. A 344 GB claim may reflect compressed archives, duplicated files, or inflated figures. Until UIC or an independent forensic partner confirms the incident, impact assessment remains speculative.

What to Watch For

  • Official statements from UIC or its designated incident response provider.
  • Regulatory filings or breach notifications that would corroborate the claim.
  • Any leak site updates, including countdown timers or partial data releases.
  • Reuse of UIC credentials in downstream credential-stuffing campaigns.
  • Related activity from Booba Project against other education sector targets.

Yazoul Security will continue monitoring this claim through our intel pipeline and will publish updates if corroborating evidence emerges.

Disclaimer

This report is based solely on an unverified claim published by a ransomware group on its leak site. Yazoul Security has NOT independently confirmed the alleged attack, the claimed data volume, or the authenticity of any exfiltrated material. Nothing in this report should be construed as a statement of fact regarding the University of Illinois Chicago. Ransomware groups frequently exaggerate or fabricate claims to pressure victims. Readers should await official confirmation before drawing conclusions.

Share:

Never miss a threat intelligence alert

Get real-time security alerts delivered to your preferred platform.

Related Claims

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.