SYS::ONLINE
Wasteland.
Briefs1575
Issues20
SinceFeb 2026
LIVE
▣ Breach MCBS-HEALTHCARE-DA 2026-07-27

MCBS: PEAR Ransomware Breach Exposes 1.2 Million Patients

"Atlanta-based Medical Computer Business Services (MCBS), a medical revenue cycle management and billing provider, has confirmed a data breach affecting more than 1.2 million individuals. According to the company's own…"

Atlanta-based Medical Computer Business Services (MCBS), a medical revenue cycle management and billing provider, has confirmed a data breach affecting more than 1.2 million individuals. According to the company's own breach notification posted to its website, attackers gained access to MCBS systems in September 2025 and potentially exfiltrated files containing personal and protected health information. The US Department of Health and Human Services breach portal lists the incident at 1,261,464 affected individuals. The PEAR ransomware group claimed responsibility in late September 2025 and says it took more than 3 TB of data.

What Happened

MCBS says hackers targeted its environment in September 2025. The subsequent investigation determined that the attackers had access to company systems over a four-day window, from September 22 through September 26, 2025. That is a short dwell time by healthcare breach standards, consistent with a smash-and-grab exfiltration operation rather than a long, quiet reconnaissance campaign.

MCBS is not a healthcare provider itself. It is a business associate under HIPAA, handling billing and revenue cycle operations on behalf of medical practices. Its breach notification names seven healthcare organizations whose data was compromised in the attack, meaning a single intrusion at one vendor cascaded into patient exposure across multiple downstream provider populations.

PEAR claimed the attack on its leak site in late September 2025 and has since made the allegedly stolen data available for download. The public release means the data is no longer a hypothetical risk held by a single actor. It is now in circulation.

What Was Taken

Per the MCBS notification, the potentially affected file types contained:

PEAR's own claims go considerably further than the notification language. The group says it stole more than 3 TB of files, including company and client financials, HR and business operations documents, partner and vendor data, patient PII and PHI records, payment details, and internal email.

That combination is the worst-case profile for a billing intermediary. SSN plus date of birth plus insurance data enables both traditional identity theft and medical identity fraud, which is harder for victims to detect and slower to unwind. The financial and vendor documents extend the blast radius to MCBS clients and partners who were never directly breached. Stolen email archives typically fuel follow-on business email compromise against the exact partner organizations named in those archives.

Why It Matters

This is a third-party risk story more than a single-victim story. Revenue cycle management vendors sit at an aggregation point: they hold complete billing records for many providers at once, which makes one successful intrusion worth many times the effort. Seven named healthcare organizations lost patient data here without any compromise of their own networks.

PEAR is also worth tracking on its own merits. The group emerged in mid-2025 and its leak site already lists more than 100 alleged victims, a fast operational tempo for a crew less than a year old. It has claimed the Motility Software Solutions breach affecting 766,000 people and the Tri-Century Eye Care breach affecting 200,000 people. The pattern across those three is consistent: mid-market service providers and specialty healthcare organizations, not hardened enterprise targets. PEAR appears to be selecting for organizations that hold high-value regulated data but are unlikely to have mature detection or 24/7 monitoring.

The four-day dwell time is the operational detail defenders should sit with. Detection controls calibrated to catch intrusions over weeks will not fire in time. By the time a quarterly review or a monthly log audit surfaces anomalies, the data is already staged, exfiltrated, and posted.

The Attack Technique

Neither MCBS nor PEAR has publicly disclosed the initial access vector, and no specific vulnerability, phishing campaign, or credential compromise has been attributed to this intrusion. What the timeline does tell us is meaningful.

Access ran from September 22 to September 26, 2025. Moving from initial foothold to multi-terabyte exfiltration in four days implies the attackers reached file servers or backup repositories quickly, which usually means either credentials with broad access from the outset or fast privilege escalation against a flat internal network. Exfiltrating 3 TB also requires sustained outbound transfer that egress monitoring or data loss prevention tooling would be expected to flag.

PEAR's public posture is data-leak-driven extortion. The group published the stolen files for download rather than holding them purely for ransom leverage, which is the pattern of an actor that either failed to secure payment or treats publication as a reputational tool to pressure future victims. Organizations facing PEAR should plan on the assumption that stolen data will be published.

What Organizations Should Do

Inventory your business associates and what they actually hold. If a billing, coding, or revenue cycle vendor has a copy of your full patient records, that vendor's security posture is your security posture. Map which third parties hold PHI and at what volume, and require breach notification terms with defined timelines in contracts.

Instrument for egress, not just entry. A 3 TB outbound transfer is detectable. Baseline normal outbound data volumes per host and per destination, and alert on deviation. Egress monitoring is the control most likely to have caught this attack inside the four-day window.

Compress your detection timeline to days, not weeks. Deploy EDR with 24/7 alerting on file server and backup infrastructure. Assume an attacker who lands on Monday is exfiltrating by Thursday, and build response capability that matches that pace.

Segment file and backup repositories. The aggregation of financials, HR files, patient records, and email into a single reachable location is what made 3 TB possible. Network segmentation and least-privilege access to bulk data stores limit what a single compromised account can reach.

Enforce phishing-resistant MFA on every remote access path. VPN, RDP, remote management tooling, and administrative consoles should require FIDO2 or equivalent. Credential-based initial access remains the most common entry for this class of intrusion.

Prepare the downstream notification path now. If you are a business associate, know which covered entities you would need to notify and how fast. If you are a covered entity, know which vendors could trigger your reporting obligations. MCBS had to name seven organizations. Determine your equivalent list before an incident forces it.

Sources: MCBS Data Breach Affects 1.2 Million Individuals