MCBS Data Breach Impacts 1.2 Million Patients

Medical Billing Firm MCBS Breach Affects 1.2M; PEAR Ransomware Blamed

CRITICAL
July 27, 2026
5m read
Data BreachRansomwareThreat Actor

Impact Scope

People Affected

1,261,464

Affected Companies

Medical Computer Business Services (MCBS)

Industries Affected

Healthcare

Geographic Impact

United States (national)

Related Entities

Threat Actors

PEAR

Products & Tech

Other

Medical Computer Business Services (MCBS) Motility Software SolutionsTri-Century Eye Care

Full Report

Executive Summary

Medical Computer Business Services (MCBS), a medical revenue cycle management firm, has disclosed a major data breach impacting 1,261,464 individuals. The breach, which occurred between September 22 and 26, 2025, involved unauthorized access to systems containing highly sensitive patient data. Compromised information includes names, Social Security numbers, dates of birth, and detailed Protected Health Information (PHI). The PEAR (Pure Extortion and Ransom) ransomware group has claimed responsibility for the attack, asserting they stole 3 TB of data and later leaked it when a ransom was not paid. This incident highlights the significant supply chain risk in the healthcare sector, where a breach at a single business associate can affect numerous provider organizations and their patients.


Threat Overview

The incident was a data exfiltration and extortion attack carried out by the PEAR ransomware group. Unlike traditional ransomware that primarily encrypts files, PEAR's main objective is data theft for the purpose of extortion. The group gained access to MCBS's network in late September 2025 and, over several days, exfiltrated a massive trove of data. This data belonged to patients of at least seven healthcare provider clients of MCBS. After the exfiltration, PEAR listed MCBS on its dark web leak site and eventually published the stolen data, exposing over 1.2 million patients to risks of identity theft and fraud.

Technical Analysis

The PEAR group, which emerged in mid-2025, specializes in data theft and extortion.

TTPs and MITRE ATT&CK Mapping

PEAR is known for similar attacks in the healthcare sector, including breaches at Motility Software Solutions (766,000 affected) and Tri-Century Eye Care (200,000 affected), demonstrating a clear pattern of targeting organizations with sensitive data.

Impact Assessment

This breach has severe consequences for the 1.26 million affected individuals. The exposure of Social Security numbers, combined with detailed medical and insurance information, creates a perfect storm for sophisticated identity theft, financial fraud, and targeted phishing attacks. For MCBS, the impact includes significant incident response costs, potential regulatory fines under HIPAA, and severe reputational damage. The seven affected healthcare organizations also face consequences, as they are ultimately responsible for protecting their patients' data, even when it is managed by a business associate. The long delay between the breach (September 2025) and notification (July 2026) is a significant compliance concern and exacerbates the risk to affected individuals.

IOCs — Directly from Articles

No specific Indicators of Compromise (IOCs) were provided in the source articles.

Cyber Observables — Hunting Hints

To detect activity similar to that of extortion groups like PEAR, security teams should hunt for the following:

Type
network_traffic_pattern
Value
Sustained, high-volume data transfers from internal servers to unknown external IP addresses, especially outside of business hours.
Description
A primary indicator of bulk data exfiltration.
Type
command_line_pattern
Value
rclone.exe, megacmd.exe
Description
Use of command-line cloud storage synchronization tools for data exfiltration.
Type
file_name
Value
*.zip, *.rar, *.7z
Description
Large archive files being created on servers that do not typically handle such data, indicating data staging.
Type
log_source
Value
DLP Alerts
Description
Data Loss Prevention (DLP) systems should be configured to alert on large movements of files containing PII/PHI patterns.

Detection & Response

  1. Data Exfiltration Monitoring: Deploy network security monitoring and DLP solutions to detect and alert on anomalous outbound data flows. Use D3FEND Network Traffic Analysis to baseline normal traffic and identify suspicious transfers.
  2. File Integrity Monitoring (FIM): Monitor critical file shares and databases for unusual read activity. A single user account accessing millions of records in a short period is a major red flag for data scraping.
  3. User and Entity Behavior Analytics (UEBA): Implement UEBA to detect compromised accounts. Look for logins from unusual locations, privilege escalations, or access to sensitive data that is outside the user's normal job function. This aligns with D3FEND User Geolocation Logon Pattern Analysis.

Mitigation

Preventing large-scale data theft requires strong access controls and data-centric security.

  1. Data Encryption: Encrypt sensitive data both at rest and in transit. While this may not stop a determined attacker with valid credentials, it adds a critical layer of defense. This is a direct application of M1041 - Encrypt Sensitive Information.
  2. Network Segmentation: Segment the network to prevent a compromise in one area from providing access to sensitive data stores. Critical databases containing PHI should be in a highly restricted network zone. This uses D3FEND Network Isolation.
  3. Least Privilege Access: Enforce the principle of least privilege for all user and service accounts. Accounts should only have access to the specific data required for their function. This is a core part of M1026 - Privileged Account Management.
  4. Third-Party Risk Management: Healthcare organizations must conduct thorough security assessments of their business associates and ensure contractual obligations for data protection are in place and audited.

Timeline of Events

1
September 22, 2025
Unauthorized access to MCBS systems begins.
2
September 26, 2025
Period of unauthorized access ends.
3
July 27, 2026
MCBS begins notifying affected individuals and reports the breach to HHS.
4
July 27, 2026
This article was published

MITRE ATT&CK Mitigations

Encrypting sensitive data at rest can make it unusable to an attacker even if they manage to exfiltrate it.

Isolating databases containing PHI/PII in secure network zones with strict access controls can prevent attackers from reaching them after an initial compromise.

Utilize DLP and network monitoring to detect and block large, anomalous outbound data transfers indicative of exfiltration.

Train employees to recognize phishing attempts to prevent the initial credential compromise that often leads to such breaches.

Timeline of Events

1
September 22, 2025

Unauthorized access to MCBS systems begins.

2
September 26, 2025

Period of unauthorized access ends.

3
July 27, 2026

MCBS begins notifying affected individuals and reports the breach to HHS.

Sources & References

MCBS Data Breach Affects 1.2 Million Individuals
SecurityWeek (securityweek.com) July 27, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

Data BreachMCBSPEAR RansomwareHealthcareHIPAAPIIPHI

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.