Insomnia is a data-theft and extortion group that emerged in October 2025, targeting primarily US-based healthcare organizations — stealing patient files and threatening public exposure rather than encrypting files — and avoiding former Soviet states, consistent with Russian-speaking cybercrime norms. Known victims: 34
Objectives
Executive Summary
Insomnia is a medium-sophistication criminal threat actor identified since February 2025, primarily targeting US-based healthcare organizations. Known for data theft and extortion via threats of public exposure rather than ransomware encryption, Insomnia demonstrates strategic operational choices, such as avoiding former Soviet states—consistent with Russian-speaking cybercrime norms. The group is considered particularly concerning due to its focus on sensitive data in the healthcare sector.
Goals & Targeting
Insomnia's strategic objectives center on financial gain through extortion and the theft of sensitive data, which they leverage for coercive purposes. Their targeting focus on healthcare organizations reflects both the availability of highly sensitive Personally Identifiable Information (PII) and the high stakes involved in protecting patient records—a sector with little tolerance for downtime or data breaches. Insomnia's geographic choices suggest an operational awareness of regional law enforcement capabilities and international relations, particularly concerning former Soviet states.
Enhanced Description
Insomnia emerged in early 2025 as a数据-theft and extortion-focused cybercriminal group. Unlike traditional ransomware operators, Insomnia specializes in stealing patient records and threatening public exposure to coerce victims into paying ransoms or other forms of compensation. This unique approach reflects a strategic shift in tactics, focusing on data integrity and privacy concerns rather than outright encryption. The group has demonstrated persistence and adaptability over its brief operational history, targeting 34 healthcare organizations across the United States as of June 2026. Insomnia's avoidance of former Soviet states aligns with broader trends observed within Russian-speaking cybercrime groups, where such geographic constraints are often imposed to minimize law enforcement attention or avoid geopolitical complications.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Insomnia operates with a steady cadence, launching multiple campaigns against healthcare organizations in the past six months. Their victims include Nephrology Associates, METO Systems, United Medical Doctors, and others in the healthcare sector. Known for their methodical approach, Insomnia uses sophisticated tactics to gain unauthorized access, exfiltrate data, and issue threats. Campaign patterns indicate a preference for email-based social engineering and lateral movement within networks.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the targeting patterns, tactics, and threat vectors attributed to Insomnia based on observed campaigns. Limited visibility into specific tools or malware used by the group, though their reliance on data exfiltration suggests use of common frameworks such as Cobalt Strike or similar. Further analysis could clarify their exact modus operandi and toolset.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
17
Campaigns
0
IOCs
0
Observed Data
0
Tactics