Following its appearance on underground leak websites in the past several weeks, Insomnia has posted 18 purported victims to its data leak platform, with over half being healthcare service providers or organizations connected to the healthcare field.
The listed organizations encompass healthcare facilities, companies providing support to medical operations, two legal practices focused on medical malpractice litigation, and a producer of surgical and medical devices. Apart from two entities situated in Brazil and Singapore, all identified victims operate within the United States.
A significant portion of the targeted healthcare-related organizations qualify as small-to-mid-sized enterprises, recording yearly revenues ranging from roughly $5 million to $57 million and employing between 11 and 200 staff members, which points to a strategy of targeting entities that likely possess fewer cybersecurity capabilities than major hospital networks.
Attempts to obtain statements from the healthcare organizations named as victims concerning the alleged security breaches have predominantly received no response.
Healthcare Sector Has Long Been Targeted for Extortion
Healthcare institutions have traditionally represented appealing targets for cyber extortion groups. Threat actors commonly believe that hospitals and healthcare facilities are more inclined to enter into negotiations or submit payments to avoid operational disruptions that might compromise patient treatment.
Nevertheless, patterns within the industry indicate this situation may be changing.
A yearly healthcare cybersecurity assessment performed by Sophos and released in October 2024 found that merely 36% of healthcare ransomware victims fulfilled ransom demands, representing a considerable decrease from the 61% payment frequency documented in 2022.
The assessment additionally noted a marked reduction in typical ransom payments. Mean payments purportedly dropped to around $150,000 in 2025, down from $1.47 million the preceding year, reflecting diminished returns for attackers and strengthened resilience among healthcare institutions.
These observations indicate that although healthcare continues to be frequently targeted, cybercriminal operations are facing heightened defensive capabilities, compelling them toward smaller, less lucrative incidents.
Insomnia’s Operational Timeline and Leak Activity
The first known posting on Insomnia’s leak platform occurred on October 8, 2025, implying operational activity commenced no later than that date, based on threat intelligence examination performed by Kela.
Kela researchers indicate that the victims identified by Insomnia do not seem to have been previously identified by recognized ransomware groups or featured on other established leak websites, suggesting that Insomnia may constitute either a novel intrusion actor or an independent monetization mechanism.
Materials shown on the leak platform encompass extremely sensitive content such as patient information and healthcare records, government-issued identification documents including driver’s licenses, tax documentation, and internal corporate correspondence containing personal and medical data.
Every currently published data collection is accessible for complimentary download, with files purportedly containing materials dated as late as January 2026. Nonetheless, independent confirmation of the legitimacy of the leaked information has not yet been publicly established.
Data Theft Over Encryption: A Stealth-Oriented Approach
Threat intelligence specialists observe that Insomnia seems to emphasize covert data theft operations instead of disruptive ransomware encryption attacks.
Based on Rapid7’s examination, the group depends extensively on credential-based access methods, encompassing credentials obtained through infostealer malware infections and exploitation of authentication bypass vulnerabilities.
After obtaining access, the attackers allegedly utilize legitimate infrastructure components, encompassing Windows Server update mechanisms and trusted administrative tools, to perform lateral movement while reducing detection.
This methodology prioritizes swift data exfiltration and operational concealment, enabling attackers to maximize leverage through disclosure of sensitive information instead of through system encryption or operational interruption.
Possible Role as Data Broker or Monetization Platform
Intelligence also points to the possibility that Insomnia may function partly as a data monetization platform or broker, either executing intrusions directly or collaborating with external access brokers who provide compromised network access.
This combined model permits monetization of stolen data even without ransomware deployment, providing flexibility in operational methods.
Currently, investigators have not discovered a negotiation portal or a ransomware variant associated with Insomnia, and surveillance efforts presently classify the operation chiefly as a data leak and extortion platform instead of a ransomware campaign.
Targeting Patterns and Possible Regional Considerations
Insomnia seems to refrain from targeting nations that were previously part of the Soviet Union, a characteristic historically linked with Russian-speaking cybercriminal groups functioning under unofficial regional safe-harbor conventions.
In the meantime, various ransomware and extortion operations persist in targeting healthcare organizations worldwide. Both established actors and recently emerging groups continue to pursue hospitals and healthcare-related companies, especially those with lower cybersecurity sophistication.
Threat intelligence surveillance reveals that no fewer than 68 healthcare organizations have already been targeted by cybercrime groups this year, with 50 of those incidents impacting U.S.-based entities, perpetuating a longstanding pattern of concentration on U.S. healthcare infrastructure.
Opportunistic Targeting Drives Continued Healthcare Risk
Analysts conclude that the targeting pattern demonstrates financially motivated, opportunistic campaigns instead of highly specialized operations. The substantial number of healthcare organizations functioning within the United States amplifies exposure and contributes to the nation’s prominence as a preferred target for cyber extortion and data theft campaigns.
As groups like Insomnia embrace stealthier data-theft-driven strategies, healthcare organizations may progressively encounter threats centered on data exposure instead of operational disruption, indicating a continued evolution in extortion tactics impacting the sector.
References:
- The Hacker Wire insomnia Ransomware
- KELA Cyber Threat Intelligence Research
- Halcyon Insomnia
- Hive Pro Insomnia: Data-Theft Extortion Operation Targeting US Healthcare