Cyber Threat Actor: Insomnia
| Actor Type | Location | Known Incidents |
Criminal
|
—
|
2 incidents |
|---|
Profile
Insomnia is the alias used to refer to the threat actor responsible for a pair of healthcare‑related data breaches disclosed in December 2025. The actor gained unauthorized access to the networks of two separate organizations and exfiltrated sensitive personal information. No public attribution to a state sponsor or criminal consortium has been made for Insomnia.
In the first incident, reported on 2025‑12‑05, Insomnia infiltrated ZenPatient, a telehealth and messaging software provider, and removed files containing names, addresses, birth dates, and medical information. The breach was detected by the company, which then engaged third‑party cybersecurity experts to confirm the intrusion. Notification letters were sent to affected individuals and complimentary credit monitoring services were offered as a mitigation step.
The second incident, disclosed on 2025‑12‑01, involved Anatomic and Clinical Laboratory Associates, where Insomnia accessed the network during a routine security review and exfiltrated a broader set of data including names, dates of birth, Social Security numbers, taxpayer identification numbers, service dates, provider names, medical conditions, treatment details, diagnoses, medical history, account numbers, and record numbers. The organization notified nearly 170,000 patients, provided complimentary credit monitoring and identity theft protection to those whose data included specific identifiers, and subsequently implemented additional security controls to reduce the risk of similar events.
Observed patterns from these incidents indicate that Insomnia focuses on the healthcare sector, targeting both software platforms that handle patient communications and laboratories that store detailed health records. The actor consistently seeks to obtain personally identifiable information and protected health information, which are then used to trigger victim‑side responses such as credit monitoring offers and security upgrades. No specific malware families, initial‑access vectors, or tooling styles have been publicly linked to Insomnia in the available reporting.
Attribution efforts have not produced a definitive link to any nation‑state, criminal alliance, or other known threat‑actor group; the actor remains publicly unattributed beyond the alias Insomnia and the two disclosed breaches. Consequently, any further conclusions about the actor’s motives, size, or geographic origin, or affiliations would be speculative and are omitted here.
