Extortion Gang PEAR Breaches Medical Billing Firm, Exposing 1.3 Million Patients' Data
Medical Cost Bảo hiểm Services LLC (MCBS) is notifying 1.3 million patients of a 2025 data breach attributed to the extortion group PEAR, which claims to have stolen 3.3 terabytes of sensitive information.

A Georgia-based medical billing firm, Medical Cost Bảo hiểm Services LLC (MCBS), is in the process of notifying approximately 1.3 million patients across seven healthcare practices about a significant data breach that occurred in 2025. The incident, which saw threat actors gain unauthorized access to MCBS's network between September 22 and September 26, 2025, has been claimed by the extortion gang known as PEAR.
PEAR, an acronym for Pure Extraction and Ransom, is identified by threat intelligence researchers as a data broker and extortion group that bypasses the encryption of victims' systems. The group first emerged in June 2025. MCBS detected the unauthorized access on September 25, 2025, and its subsequent investigation confirmed that threat actors had potentially accessed or removed certain files within a four-day window.
The compromised data includes a wide range of sensitive personal and health information. Affected files contained patient names, addresses, Social Security numbers, dates of birth, health plan beneficiary numbers, health insurance policy or subscriber identification numbers, other health insurance details, medical history, mental or physical condition information, medical treatment details, and diagnosis information. The specific data points vary for each affected individual.
The breach impacted patients of seven specific MCBS clients: C&C MD; Nuclear Medicine and Pathology Associates; Radiation Oncology Associates; SkinPath Solutions; South Georgia Radiology Consultants; Stephen W. Brown & Radiology Associates of Augusta; and Vascular Radiology Associates II. Despite the sensitive nature of the exfiltrated data, MCBS stated that it has found no evidence of identity theft resulting from this incident.
However, PEAR has publicly claimed on its dark web site to possess 3.3 terabytes of MCBS data, including financial, human resources, business operations, and payment information belonging to both the billing firm and its clients, alongside the patients' protected health information (PHI) and personally identifiable information (PII). This claim places the incident among the largest health data breaches reported in 2026.
MCBS is now facing legal repercussions, with at least one proposed federal class action lawsuit filed against it. The lawsuit alleges that PEAR successfully breached and exfiltrated highly sensitive data from the firm's "inadequately protected computer systems." MCBS has not yet responded to requests for comment regarding PEAR's dark web claims or further details about the breach.
Research from cyber insurance and security services firm At-Bay indicates that as of February 2026, PEAR had targeted at least 51 victims across various sectors, including healthcare, business services, manufacturing, and technology, with average ransom demands of $550,000. At-Bay's investigation suggests PEAR commonly gains initial access through compromised virtual private network credentials, subsequently deploying legitimate remote management tools like AteraAgent and Splashtop Remote Service rather than custom malware.
PEAR's operational tactics include using common tools like PsExec for remote execution and credential dumping utilities to extract passwords from memory. For data exfiltration, the group relies on file transfer applications such as RClone and WinSCP. This "living off the land" approach presents a detection challenge for defenders, as the tools used have legitimate administrative purposes. The group is also known for its aggressive communication tactics, directly contacting employees via text messages and WhatsApp to claim data theft, distinguishing itself from other ransomware operations.