Insomnia is a cybercriminal group that began operations in October 2025, focusing on data theft and extortion without encrypting systems. It primarily targets small to mid-sized organizations, particularly in the healthcare sector, using stolen credentials and legitimate tools to evade detection.
Key insights
•Insomnia uses stolen credentials and exploits authentication bypass vulnerabilities for initial access.
•The group targets primarily healthcare organizations, threatening public exposure of sensitive data at risk of leakage.
•Insomnia maintains a low profile during lateral movements by using legitimate administrative tools.
•The operational model avoids ransomware, instead relying on the threat of data leaks for financial gain.
•They often steal sensitive records like patient files and tax documents but do not engage in data encryption.
•Insomnia's tactics focus on speed and low visibility, complicating traditional detection methods.