VYPR
breachPublished Jul 27, 2026· 1 source

MCBS Data Breach Exposes Sensitive Information of Over 1.2 Million Individuals

Medical business management company MCBS has confirmed a significant data breach impacting approximately 1.2 million individuals, with ransomware group PEAR claiming responsibility for exfiltrating terabytes of sensitive data.

Atlanta-based MCBS (Medical Computer Business Services), a provider of medical revenue cycle management and billing services, has disclosed a substantial data breach that occurred in September 2025, affecting an estimated 1.2 million individuals. The breach, which saw attackers gain access to MCBS systems between September 22 and September 26, 2025, potentially exposed a wide range of sensitive personal and health information.

The compromised data may include individuals' names, addresses, Social Security numbers, dates of birth, health insurance details, and medical records. The full extent of the exfiltrated information is still under investigation, but the implications for affected individuals are significant, given the sensitive nature of the data.

According to the U.S. Department of Health and Human Services' healthcare data breach tracker, the incident impacts at least 1,261,464 individuals. The notification also specifically names seven healthcare organizations whose data was compromised as a result of this cyberattack, highlighting the interconnectedness of healthcare data management.

The ransomware group PEAR has claimed responsibility for the attack, asserting that they exfiltrated over 3 terabytes of data. Their claims include the theft of company and client financials, HR and business operations documents, partner and vendor data, patient Personally Identifiable Information (PII) and Protected Health Information (PHI) records, payment details, and emails. PEAR has reportedly made some of the allegedly stolen data available for download, increasing the pressure on MCBS and its clients.

PEAR is a relatively new but active ransomware group that emerged in mid-2025. Its leak website has listed over 100 alleged victims, indicating a significant operational capacity. The group has also claimed responsibility for other notable breaches, including attacks on Motility Software Solutions, which affected 766,000 people, and Tri-Century Eye Care, impacting 200,000 individuals, underscoring their broad targeting strategy.

The breach at MCBS serves as a stark reminder of the persistent threats facing the healthcare sector and its associated business service providers. The exfiltration of such a large volume of sensitive data raises concerns about potential identity theft, financial fraud, and further downstream attacks targeting individuals and the named healthcare organizations.

As investigations continue, MCBS is expected to provide further updates and guidance to affected individuals. The incident underscores the critical need for robust cybersecurity measures, particularly for third-party vendors handling sensitive patient data, and highlights the ongoing challenges in protecting health information from sophisticated ransomware operations.

Synthesized by Vypr AI