LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Metropolitan Community Health Services Listed by Insomnia Ransomware Group

HIGH severityUnverified claimHow we verify

Metropolitan Community Health Services Listed by Insomnia Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 14, 2026
Metropolitan Community Health Services Listed by Insomnia Ransomware Group

Reported September 14, 2026.

HIGH
Severity
September 14, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Metropolitan Community Health Services was listed by the Insomnia ransomware group on September 14, 2026, with the group claiming it holds data on an undisclosed number of individuals. People who have used the organisation’s services should check official updates and follow guidance on protecting their personal information.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

A ransomware group known as Insomnia has listed Metropolitan Community Health Services on its leak site, according to a report dated September 14, 2026. The listing is an unverified claim. As of writing, the organisation has not publicly confirmed that an incident occurred, that systems were accessed, or that any patient or staff information left its control. People who receive care through its programmes, including Agape Health Services, may still want to understand what such a listing does and does not establish, and what practical steps are reasonable if their information were ever involved.

Community health providers hold sensitive personal and clinical details as a normal part of care. When a group posts a name on an extortion site, the immediate stakes for patients and families are uncertainty: whether anything was taken, what it might include, and whether it could be misused. Public detail on this listing is limited. The number of people potentially affected is unknown, and the types of data the group claims to hold have not been disclosed in the material summarised here.

Inside the listing

Insomnia has named Metropolitan Community Health Services on its leak site. The reported date associated with that listing is September 14, 2026. Beyond the organisation’s name and the group’s attribution, the available summary does not describe how any alleged intrusion would have occurred, whether ransomware was deployed, whether files were copied, or whether a deadline or sample material was posted. Scale is undisclosed: there is no figure for affected individuals, accounts, or records.

The listing should be read as an accusation used for pressure, not as a confirmed inventory of events. Ransomware crews sometimes recycle older material, exaggerate access, or list organisations incorrectly. Nothing in the facts provided establishes that Metropolitan Community Health Services systems were compromised, that data left the organisation, or that the group’s marketing description of a haul is accurate. The company has not, on the public record reflected here, confirmed the incident.

The group behind it: Insomnia

Insomnia is known in public reporting as a ransomware and data-extortion actor. Groups in this category typically claim to encrypt systems or steal copies of data, then threaten publication on a leak site unless a payment is made. Their posts are designed to create urgency for the named organisation and anxiety for anyone who might appear in stolen files. Tactics associated with such crews in general include double extortion—pairing encryption claims with alleged data theft—and staged releases meant to prove access. Those patterns are background on how the ecosystem works; they are not proof of what happened in this specific case.

For this listing, only what the facts state can be tied to Metropolitan Community Health Services: the group has listed the organisation, the report date is September 14, 2026, affected-person counts are unknown, and data types are not disclosed. Any broader claim the group may make about file contents or internal systems remains the group’s assertion unless independently confirmed by the organisation or a regulator.

Who is Metropolitan Community Health Services?

Metropolitan Community Health Services is associated with Agape Health Services, described as a Certified Community Behavioral Health Clinic (CCBHC) and Federally Qualified Health Center (FQHC). In that role it offers sliding-scale primary care, preventive services, dental care, pharmacy support, and behavioral health care. The same public description notes mobile services, work connected to law enforcement, training, and reentry support. Organisations of this kind serve people who may already face economic, housing, or justice-system pressures, and they sit at the intersection of medical, behavioral, and social support.

A leak-site listing aimed at such a provider is consequential because of the sensitivity of the relationships involved—not because the listing itself proves a breach. Patients and clients often share identification details, insurance or payment information, clinical histories, medications, and behavioral-health notes in order to receive care. Staff and partner agencies may also appear in administrative systems. Even an unconfirmed claim can prompt worry in a community that depends on continuity of care and trust in confidentiality.

What data was at risk

The facts state that data types named as exposed are not disclosed. It is therefore not possible to say from this record what, if anything, was copied or published. Asserting a specific category of stolen data would go beyond what is known.

If files from a CCBHC/FQHC-style provider were ever taken, organisations in this sector typically hold records that can include names, contact details, dates of birth, government or insurance identifiers, appointment and billing information, clinical notes, prescriptions, dental charts, and behavioral-health documentation. Some programmes also maintain information related to mobile outreach, training, or reentry services, which can touch criminal-justice or social-service contexts. Those are sector norms, not a confirmed contents list for this listing. Whether any such material is involved here remains unconfirmed, and the group’s own descriptions on a leak site are marketing under extortion pressure, not an audited inventory.

The real-world impact

For individuals, the practical risk if personal or health information may have been exposed includes phishing and social-engineering attempts that reference real appointments or providers, attempts to open credit or benefits accounts with stolen identifiers, and distress from the idea that sensitive behavioral or medical details could circulate. Health-related data can be used to craft convincing scams or to pressure people who fear stigma. Those harms are conditional: they depend on whether data was actually taken and what it contained—points this listing does not establish in the public summary given.

For the organisation, a public extortion listing can disrupt operations through reputational strain, diversion of staff time, and the need to investigate and communicate carefully even when claims are unproven. Partners, regulators, and patients may ask questions the public record cannot yet answer. None of that equates to a finding that a breach occurred or that any particular security failure took place; a leak-site post alone does not settle those questions.

Because the number of people affected is unknown and data types are undisclosed, there is no reliable way for a reader to know from this article alone whether they are personally implicated. The responsible stance is caution without assuming the worst as fact.

What to do now

If you receive care from Metropolitan Community Health Services or Agape Health Services, treat unsolicited messages that cite this listing with skepticism. Verify any request for personal information, payments, or password resets through official channels you already trust, not through links or numbers in unexpected emails or texts. Consider monitoring bank, credit, and insurance statements for activity you do not recognise, and use fraud alerts or credit freezes if you believe identity details could be misused. If you have evidence of misuse, report it to the relevant financial institution and, where appropriate, to consumer-protection or law-enforcement contacts in your area.

Watch for formal notices from the organisation or from regulators; confirmed incidents involving health data in the United States often trigger specific patient-notification duties, but no such confirmation is reflected in the facts here. You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach datasets unrelated to this claim—useful hygiene when any health-sector name surfaces on a leak site. Keep expectations measured: a scan of public breach corpora will not prove or disprove Insomnia’s listing, and it cannot inventory clinical files. It can only help you see whether your email is already circulating in other documented dumps.

Public detail on this matter remains limited. Insomnia has listed Metropolitan Community Health Services; the organisation has not publicly confirmed the claim as of writing; affected counts and data types are unknown or not disclosed. Further clarity, if it comes, will need to come from the organisation, independent investigators, or official notices—not from the extortion site’s claims alone.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

CompanyMetropolitan Community Health Services security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Metropolitan Community Health Services’s full breach history →
RelatedMore incidents at Metropolitan Community Health Services

More recent breaches

Massey, Stotser & Nichols Listed by Insomnia Ransomware GroupSeptember 14, 2026NorthShore Health Centers Listed by Insomnia Ransomware GroupSeptember 7, 2026Maglin, Miskiv & Associates Listed by Insomnia Ransomware GroupSeptember 3, 2026Metro Tulsa Foot Listed by Insomnia Ransomware GroupAugust 31, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Metropolitan Community Health Services Listed by Insomnia Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by insomnia — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram