Insomnia is an emerging cybercriminal extortion group that surfaced in late 2025 and became publicly visible in early 2026. The actor is primarily associated with data-theft extortion rather than conventional ransomware encryption, operating a leak site where allegedly stolen victim data is exposed or offered for download to pressure organizations. Security reporting consistently indicates a strong concentration on healthcare-related targets, especially small to mid-sized healthcare providers and adjacent organizations, with more than half of its publicly listed victims tied to the medical sector. Insomnia’s victimology is heavily U.S.-centric, although limited non-U.S. victims have also been observed. Publicly claimed victims include clinical laboratories, medical practices, dialysis and specialty care providers, and other healthcare-linked entities. The group has also targeted organizations connected to healthcare services, including legal and medical-product businesses. Observed tradecraft indicates a stealth-focused intrusion model optimized for rapid data acquisition and extortion leverage. Reported access methods include credential-based intrusion, including use of credentials obtained via infostealer activity, exploitation of authentication-bypass vulnerabilities, and abuse of legitimate infrastructure for lateral movement. The group appears to prioritize low-visibility operations, sensitive-data collection, and post-compromise monetization over disruptive encryption. Analysts have not consistently linked Insomnia to a distinct ransomware encryptor or negotiation portal, and it is often characterized as a data-leak or data-theft extortion operation rather than a mature encryption-centric ransomware program. Insomnia has publicly claimed compromises affecting healthcare organizations such as Anatomic and Clinical Laboratory Associates and Valley Family Health Care, and has been associated with leak-site postings involving protected health information and other sensitive personal records. Reporting also notes that the group may function in part as a broker or platform for monetizing stolen data. Its apparent avoidance of former Soviet states has been cited as behavior consistent with Russian-speaking cybercriminal safe-harbor norms, but attribution to a specific state or direct state sponsorship is not established. The actor’s dominant motivation is financial gain through extortion and monetization of stolen data. Known aliases are limited, and the group is most commonly tracked simply as Insomnia.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed responsibility for the cyber attack on Anatomic and Clinical Laboratory Associates and listed the organization on its leak site; also announced the hacking of 17 healthcare organizations, 16 of them in the United States.
Named as the threat actor claiming responsibility for the Southern Illinois Dermatology data breach.
Named as the group claiming a ransomware-related healthcare data breach affecting Southern Illinois Dermatology.
Conducting data extortion/leak-site operations against Valley Family Health Care, claiming to have exfiltrated more than one million records containing sensitive patient and insurance information and later dumping the data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.