Agape Health Ransomware Claim by insomnia (Aug 2026)
Unverified dark web claim. This report is based on a post observed on a dark web forum. Yazoul Security has not independently verified the authenticity of this claim.
Leak Site Screenshot
Screenshot captured at time of discovery. Image blurred to protect victim PII.
Claim Summary
On or around August 24, 2026, the ransomware group tracked as “insomnia” allegedly posted Metropolitan Community Health Services to its dark web leak site. The organization operates Agape Health Services, a community behavioral health center (CCBHC) and federally qualified health center (FQHC) based in the United States.
According to the threat actor’s claim, the victim provides sliding-scale primary care, preventive services, dental, pharmacy, and behavioral health care, along with mobile health, law-enforcement partnership, training, and reentry programs. The group has not disclosed a data volume, sample files, or proof-of-compromise artifacts in the listing as observed.
This claim has NOT been independently verified by Yazoul Security. It remains a single-source assertion published by the threat actor itself.
Threat Actor Profile
The group operates under the name insomnia. At the time of writing, Yazoul Security has no public research references, no confirmed tooling fingerprints, and no reliable victim-count baseline for this actor. Its total known victim count is listed as unknown.
Because of this thin public footprint, several possibilities remain open:
- insomnia may be a newly emerged or rebranded operation.
- It may be a low-volume actor that publishes sporadically.
- It may be an established group using a fresh alias to complicate attribution.
No YARA rules, TTP signatures, or detection guidance specific to insomnia are currently available in our tracking. Analysts should treat any tooling attribution as speculative until corroborated. Where detection coverage exists, it should rely on generic ransomware precursors: unusual data staging, mass file access, and outbound transfer anomalies rather than actor-specific indicators.
Alleged Data Exposure
The leak site entry allegedly references the victim’s service lines rather than specific data categories. No sample records, file trees, or credential dumps have been observed in connection with this claim.
Healthcare FQHCs and CCBHCs typically hold highly sensitive categories of information, which could include:
- Patient health records and behavioral health notes
- Insurance and billing data
- Pharmacy and prescription records
- Employee and contractor information
- Grant, compliance, and operational documentation
None of the above is confirmed as exfiltrated. The absence of published samples is notable. Some actors withhold proof to pressure negotiations, while others post claims before exfiltration is complete or verified.
Potential Impact
If the claim is accurate, potential consequences could include regulatory exposure under HIPAA, notification obligations across multiple states, and disruption to care delivery for underserved populations. Community health centers often operate on thin margins, which can amplify operational and financial strain.
That said, ransomware groups routinely exaggerate scale, inflate data sensitivity, and recycle claims to manufacture urgency. A leak site post alone is not evidence of data theft.
What to Watch For
- Publication of sample data or a countdown timer on the leak site
- Direct confirmation or denial from Metropolitan Community Health Services
- Regulatory filings or breach notifications in affected states
- HHS OCR breach portal entries
- Any shift in the actor’s naming conventions suggesting a rebrand
Yazoul Security will update this report if corroborating evidence emerges. See our intel hub for related tracking.
Disclaimer
This report is based solely on an unverified claim published by a ransomware group. Yazoul Security has NOT independently confirmed the breach, the scope of any data exposure, or the authenticity of the actor’s statements. Nothing here should be treated as fact. No personal data, credentials, samples, or access instructions are included by design. Organizations should verify through their own incident response and legal channels before acting on this information.
Never miss a threat intelligence alert
Get real-time security alerts delivered to your preferred platform.
Related Claims
Imperial Healthcare Solutions — qilin
www.ibnsinatrust.com — krybit
amorsaude.com.br — lockbit5
General Santos Doctors Hospital — rhysida