Ransomware victim disclosure
← All victimsAurora Health Management
Claimed by Insomnia · listed 3 hours ago
Status timeline
- ListedAug 19, 2026
- Data leakeddate unknown
At a glance
- Group
- Insomnia
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Aug 19, 2026
About the victim
AI dossier — public-source company profileAurora Health Management, LLC operates a skilled nursing and rehabilitation center in Frederick, Maryland, specializing in long-term care with approximately 25 years of operational history. The company focuses on improving facility operations through comprehensive management programs and maintaining Medicare/Medicaid compliance standards.
- Industry
- Skilled Nursing & Rehabilitation Services
- Address
- Frederick, MD
Attack summary
Severity: high — Healthcare provider with patient records at risk; skilled nursing facilities typically hold PII, medical records, and insurance information. Data has been published and disclosed status confirms exfiltration occurred, though specific data inventory is not detailed in the post.The insomnia group claims to have conducted an attack on Aurora Health Management and published data. The leak post does not specify whether encryption, exfiltration, or both occurred, nor does it detail what specific data categories were compromised.
What the group claims
Aurora Health Management, LLC operates a skilled nursing and rehab center in Frederick, MD. With nearly 25 years in long-term care, it improves troubled facilities through comprehensive management, programs, and Medicare/Medicaid standards.
The leak post
captured from the group's siteAurora Health Management, LLC operates a skilled nursing and rehab center in Frederick, MD. With nearly 25 years in long-term care, it improves troubled facilities through comprehensive management, programs, and Medicare/Medicaid standards.
Sources
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

