MCBS Breach: PEAR Ransomware Steals 3 TB of Healthcare and Personal Data of Over 1.2 Million Patients

The PEAR ransomware group stole 3TB of data from MCBS, affecting over 1.2 million patients. Learn about the healthcare data breach impact and mitigation.

MCBS Breach: PEAR Ransomware Steals 3 TB of Healthcare and Personal Data of Over 1.2 Million Patients
Data Breaches

Illustrative image generated with AI

Introduction

A massive cyber breach has hit Medical Computer Business Services (MCBS), an Atlanta-based company specializing in revenue cycle management and billing for the healthcare sector. The attack, which occurred in September 2025, resulted in the exfiltration of more than 3 terabytes of data, which the PEAR ransomware group has already published on its leak portal. According to official notifications, the incident affects 1,261,464 individuals and seven healthcare organizations that are MCBS clients.

Technical Analysis

Unauthorized access to MCBS systems was possible between September 22 and 26, 2025. During that time window, attackers stole an enormous amount of files containing full personal details (name, address, date of birth), Social Security numbers, health insurance information, and clinical documentation. The variety of stolen data – financial, human resources, emails, patient PII and PHI – indicates a deep compromise of the company's infrastructure.

The criminal group behind the attack, PEAR, emerged in mid-2025 and quickly established itself by adopting the double extortion technique: first it encrypts data to block the victim's operations, then threatens to publish it if the ransom is not paid. With over 100 claimed victims, PEAR is already responsible for other large-scale attacks in the healthcare and medical sector, including those on Motility Software Solutions (766,000 individuals affected) and Tri‑Century Eye Care (200,000 people). The publication of MCBS data on the leak site confirms either non‑payment of the ransom or the group's intent to maintain pressure on victims.

Impact

The exposure of highly sensitive personal and healthcare data exposes the involved individuals to a high risk of identity theft and insurance fraud. With clinical information and SSNs in the hands of criminals, victims could face years of targeted phishing attempts, fake reimbursement claims, or fraudulent credit line openings.

For MCBS and its client healthcare facilities, the incident entails reputation damage that is hard to quantify and possible legal and regulatory consequences, including penalties for violating healthcare data protection regulations (such as HIPAA in the United States). The uncontrolled disclosure of files, moreover, amplifies the damage in the long term, as the data remains accessible to anyone intending to use it for further attacks.

Mitigation

MCBS has published an official breach notice on its website, but at present no technical measures taken to contain the incident have been disclosed, nor any offer of identity protection services to those affected. In the absence of details, anyone who believes they are involved should:

  • Carefully monitor their financial accounts and insurance reports;
  • Activate a credit monitoring service or freeze their credit profile with major bureaus;
  • Exercise extreme caution with suspicious emails, SMS, or phone calls, avoiding sharing personal data.

Organizations handling healthcare data are urged to review their ransomware defenses, adopting multi‑factor authentication, offline backups, network segmentation, and periodic attack simulations.

FAQ

1. What data was stolen in the MCBS attack?
The exfiltrated data includes name, address, Social Security number, date of birth, health insurance information, and clinical data. Additionally, the PEAR group claims to have stolen financial documents, human resources files, emails, and payment details, totaling over 3 TB.

2. How can I tell if I am one of the victims?
MCBS has sent individual notifications to affected parties, but due to the high number of people impacted (1,261,464) and the data publication, it is advisable to directly verify your exposure through credit monitoring services or by looking for communications from the healthcare providers where you received services. Contacting MCBS or your healthcare provider can provide confirmation.

3. What can I do to protect myself after this breach?
In addition to financial and insurance checks, it is advisable to change passwords associated with online services, enable two‑factor authentication wherever possible, and be wary of any unsolicited communication requesting personal data. Considering a credit freeze can prevent new accounts from being opened in your name without authorization. In case of fraudulent use of healthcare data, immediately contact your insurer and the relevant authorities.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →