Ransomware Group Insomnia Claims Attack on Medical Records Firm Praxis EMR

A criminal gang that has claimed 53 victims since February has listed an American electronic health records company on its dark-web shaming site. The company has not confirmed anything.

ThreatVectr NewsdeskAI-assistedPublished · Editor: Lee Brown· 3 min read
Illustration: A dimly lit server room with rows of blinking rack-mounted hardware
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Insomnia listed Praxis EMR, a US-based electronic health records software company, on its dark-web leak site; monitoring service Ransomware.live first observed the listing on 2026-10-05.
  • The group's own post is dated 2026-09-17, meaning the listing sat undetected for roughly two weeks before surfacing publicly.
  • Threat Vectr's leak-site tracking has recorded 53 claimed victims for Insomnia since 2026-02-07, with healthcare its most targeted sector.
  • Five fresh victims were listed by Insomnia in the past 30 days, suggesting the group is still actively operating.
  • Praxis EMR has not publicly confirmed any incident, and the claim could not be independently verified at publication.

Praxis EMR makes software that doctors and medical providers use to store and manage patient records. That kind of tool, called an EHR (electronic health record) system, sits at the centre of a medical practice's data: appointments, clinical notes, patient histories. It's exactly the kind of target a ransomware gang, a criminal group that breaks into systems and threatens to publish stolen files unless paid, wants to hit.

On 2026-09-17, according to the group's own post, Insomnia added Praxis EMR to its dark-web leak site. These sites work as pressure tools: by threatening to publish stolen data, attackers try to force payment. Ransomware.live spotted the listing on 2026-10-05, roughly two weeks later.

How serious is this group?

Insomnia isn't new, and it isn't slowing down. Threat Vectr's tracking of criminal leak sites has recorded 53 claimed victims across 11 sectors since 2026-02-07, five of them listed in the past 30 days. Healthcare is its most frequently targeted sector. This is the fourth unconfirmed healthcare ransomware claim we've covered since late August, following a listing against St. Francis Healthcare Systems of Hawaii on 4 October.

Those figures count criminal claims, not confirmed breaches. Ransomware groups exaggerate, and occasionally fabricate listings entirely to damage a reputation or bait a payment. Every number here comes from what criminals chose to publish.

Praxis EMR has made no public statement. No confirmation exists that any patient data was taken.

What should patients and staff do right now?

Because a company is named in a listing, fraudsters sometimes use the resulting coverage to run scams. A few precautions cost nothing.

Watch for phishing emails, fake messages designed to trick you into surrendering a password or clicking a harmful link, that invoke a "Praxis data breach" to seem credible. Any call or email offering breach compensation or asking you to verify your identity because of this story should be treated as suspicious. If you reuse passwords across multiple accounts, change them: credential reuse is one of the simplest ways attackers move from one service to another.

Enable MFA, multi-factor authentication (the extra login step that sends a code to your phone or an app), wherever you can. It adds meaningful protection even when a password leaks.

If you work at a practice using Praxis EMR, watch the company's official channels for any formal notice. Don't rely on third-party summaries for guidance on whether your specific data is involved.

A criminal gang claims it broke into a medical software company's systems. That claim may be true, may be exaggerated, or may be entirely false. Until Praxis EMR says otherwise, that's all anyone outside the company can honestly say.

© 2026 Threat Vectr