1,261,464
Medical Computer Business Services (MCBS), a medical revenue cycle management firm, has disclosed a major data breach impacting 1,261,464 individuals. The breach, which occurred between September 22 and 26, 2025, involved unauthorized access to systems containing highly sensitive patient data. Compromised information includes names, Social Security numbers, dates of birth, and detailed Protected Health Information (PHI). The PEAR (Pure Extortion and Ransom) ransomware group has claimed responsibility for the attack, asserting they stole 3 TB of data and later leaked it when a ransom was not paid. This incident highlights the significant supply chain risk in the healthcare sector, where a breach at a single business associate can affect numerous provider organizations and their patients.
The incident was a data exfiltration and extortion attack carried out by the PEAR ransomware group. Unlike traditional ransomware that primarily encrypts files, PEAR's main objective is data theft for the purpose of extortion. The group gained access to MCBS's network in late September 2025 and, over several days, exfiltrated a massive trove of data. This data belonged to patients of at least seven healthcare provider clients of MCBS. After the exfiltration, PEAR listed MCBS on its dark web leak site and eventually published the stolen data, exposing over 1.2 million patients to risks of identity theft and fraud.
The PEAR group, which emerged in mid-2025, specializes in data theft and extortion.
T1190 - Exploit Public-Facing Application or T1078 - Valid Accounts obtained via phishing or credential stuffing.T1560 - Archive Collected Data to stage it for exfiltration.T1041 - Exfiltration Over C2 Channel or T1567 - Exfiltration Over Web Service.T1498 - Network Denial of Service in a reputational sense, and falls under the broader strategy of double extortion.PEAR is known for similar attacks in the healthcare sector, including breaches at Motility Software Solutions (766,000 affected) and Tri-Century Eye Care (200,000 affected), demonstrating a clear pattern of targeting organizations with sensitive data.
This breach has severe consequences for the 1.26 million affected individuals. The exposure of Social Security numbers, combined with detailed medical and insurance information, creates a perfect storm for sophisticated identity theft, financial fraud, and targeted phishing attacks. For MCBS, the impact includes significant incident response costs, potential regulatory fines under HIPAA, and severe reputational damage. The seven affected healthcare organizations also face consequences, as they are ultimately responsible for protecting their patients' data, even when it is managed by a business associate. The long delay between the breach (September 2025) and notification (July 2026) is a significant compliance concern and exacerbates the risk to affected individuals.
No specific Indicators of Compromise (IOCs) were provided in the source articles.
To detect activity similar to that of extortion groups like PEAR, security teams should hunt for the following:
network_traffic_patterncommand_line_patternrclone.exe, megacmd.exefile_name*.zip, *.rar, *.7zlog_sourceDLP AlertsPreventing large-scale data theft requires strong access controls and data-centric security.
M1041 - Encrypt Sensitive Information.M1026 - Privileged Account Management.Encrypting sensitive data at rest can make it unusable to an attacker even if they manage to exfiltrate it.
Isolating databases containing PHI/PII in secure network zones with strict access controls can prevent attackers from reaching them after an initial compromise.
Utilize DLP and network monitoring to detect and block large, anomalous outbound data transfers indicative of exfiltration.
Train employees to recognize phishing attempts to prevent the initial credential compromise that often leads to such breaches.
Unauthorized access to MCBS systems begins.
Period of unauthorized access ends.
MCBS begins notifying affected individuals and reports the breach to HHS.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.