Insomnia has posted five victims in the past 30 days, a pace consistent with near-weekly claims since its first appearance on tracking systems in June 2026, with targets spanning behavioral health, manufacturing, legal, and defense-services firms rather than a single concentrated sector. The group is described in its own materials as a data-theft and extortion operation that skips encryption in favor of stealing files and threatening public exposure, and it claims a US focus while avoiding former Soviet states, a pattern often associated with Russian-speaking crews, though that claim is unverified. Named victims so far include a behavioral health provider, a woodworking company, an engineering firm, and a public defender's office, suggesting opportunistic targeting rather than a strict industry playbook. No MITRE ATT&CK technique set has been catalogued for this group yet, so tooling and intrusion methods remain unconfirmed. With only nine total claims logged since June, Insomnia remains a small but active extortion outfit still establishing a consistent operational footprint.