Optimum Health Institute 2026 Data Breach

Optimum Health Institute Holistic Wellness Retreat Breach (2026): 69K Contact Records Exposed

Wellness Organization · Holistic wellness retreats and residential health programs · Holistic wellness retreat center · USA

Optimum Health Institute Holistic Wellness Retreat Breach (2026): 69K Contact Records Exposed

Faith-based holistic wellness and healing retreat organization

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
38/100
Lower riskHigher risk
Moderate: notable exposure with meaningful misuse potential.
Data Sensitivity i
Standard
Exposed data is largely lower-sensitivity. Standard identity-protection precautions are advised.
69KRecords
2026Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Classification Tags
InsomniaRansomware / ExtortionNonprofitWellness2026

Breach Summary

In February 2026, the INSOMNIA extortion group claimed a breach of Optimum Health Institute, a faith-based holistic wellness retreat organization (Lemon Grove, CA and Austin, TX). The incident was identified around February 8-9, 2026. The confirmed circulating data was limited to email addresses and phone numbers for approximately 68,683 individuals; no financial, identity-document, or clinical data was confirmed. Public detail is limited and OHI had not issued a detailed confirmation as of the latest reporting.

Full threat analysis, exploitation vectors, and principal guidance below.

11 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

69K records analyzed

About Optimum Health Institute

Optimum Health Institute (OHI) is a faith-based holistic wellness and healing retreat organization affiliated with the Free Sacred Trinity Church, operating residential programs (raw-food nutrition, detox, and spiritual/wellness practices) at locations in the San Diego area (Lemon Grove, California) and Austin, Texas. It collects guest reservation, contact, intake, and program-participation records to manage multi-week retreat stays.

Why They Hold Your Data

Holistic wellness retreats collect client identity, contact details, booking records, payment-adjacent information, residential-stay data, and health- or wellness-related participation records.

Recent Developments

The INSOMNIA extortion group claimed a breach of Optimum Health Institute, which was identified around February 8-9, 2026. Details of the exposed data were limited; the confirmed circulating set was contact information (emails and phone numbers).

Data Points Exposed

2 verified field types
Email Address
Phone Number

Breach Impact

Because the confirmed exposure is limited to contact data (emails and phone numbers) for roughly 69,000 individuals, the primary risk is phishing, smishing, and reservation- or wellness-themed scams. Appearing in the dataset does signal participation in a faith-based holistic-wellness program, a mild lifestyle/health-adjacent sensitivity, but no financial, identity-document, or clinical data was confirmed exposed.

Exploitation & Downstream Threats

• Targeted phishing and smishing using exposed emails and phone numbers | • Reservation- and wellness-program-themed scams | • Profiling based on wellness-retreat participation

Principal Risk Advisory

What this means for a principal

A consumer-service breach: contact and account data supports phishing, account takeover and profile enrichment. For a high-profile principal the main risk is credible impersonation and enrichment of existing exposure.

What You Should Do

  1. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  2. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
I
Threat Actor: InsomniaConfidence: Medium
Data extortion group

Motivation: Financial extortion
A data-theft-and-extortion group that emerged October 2025 focused on stealing files (patient records, drivers licenses, tax forms) and threatening exposure rather than encrypting; over half its early victims are US healthcare organizations.

Read the full threat-actor profile →

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation