Resolved High impact Ransomware Checked 6d ago

MCBS medical billing breach exposes 1.26 million records

Medical Computer Business Services, an Atlanta-based medical billing and revenue cycle company, has confirmed that attackers broke into its network in late September 2025 and stole patient data. The company began notifying more than 1.2 million affected people in July 2026, about eight months after its investigation ended. The PEAR ransomware group has claimed responsibility and says it stole 3 terabytes of data.

Started
Sep 22, 2025
Latest activity
Jul 27, 2026
Closed out
Jul 27, 2026
Attributed to
PEAR ransomware groupSuspected
Where
United States
Sectors
Healthcare
Scale
one medical billing vendor whose breach affects more than 1.26 million patients across its healthcare-provider clients

Current status

As of July 27-28, 2026 MCBS had finished its investigation and was sending breach notification letters to affected individuals, with no reports of ongoing attacker access or new victims since then.

Resolved: Services were restored and the incident was closed out.

Who is behind it

Security press reporting attributes the breach to the PEAR ransomware group based on the group's own claims on its leak site; MCBS itself has not named an attacker.

Impact

Attackers accessed MCBS systems for about four days in September 2025 and stole patient data that the PEAR group claims totals 3 terabytes; more than 1.26 million people are being notified that their personal and health information was exposed.

What to do

Anyone who gets a breach notification letter from MCBS should read it carefully, sign up for any free credit monitoring offered, and watch bank and insurance statements for unfamiliar activity.

Timeline

  1. Jul 27, 2026

    SecurityWeek reported the finalized total of more than 1.2 million individuals affected.

    Resolvedsecurityweek.com
  2. Jul 27, 2026

    SecurityWeek confirmed the PEAR ransomware group's claim of stealing about 3 terabytes of data from the Atlanta-based company.

    Resolvedsecurityweek.com
  3. Jul 14, 2026

    MCBS began notifying more than 1.26 million affected individuals after finishing its investigation.

    Resolvedesecurityplanet.com
  4. Jul 14, 2026

    MCBS began notifying more than 1.26 million affected individuals that their data was exposed.

    Resolvedesecurityplanet.com
  5. Jul 10, 2026

    The PEAR ransomware group publicly claimed the attack and said it stole about 3 terabytes of data from MCBS.

    Containedneuracybintel.com
  6. May 30, 2026

    MCBS wrapped up its internal investigation into the scope of the breach roughly eight months after the intrusion.

    Containedesecurityplanet.com
  7. Sep 22, 2025

    Attackers gained unauthorized access to MCBS network systems, an intrusion that continued through September 26, 2025.

    Containedesecurityplanet.com
  8. Sep 22, 2025

    Attackers gained unauthorized access to the MCBS network, an intrusion that continued through September 26, 2025.

    Activeesecurityplanet.com

Sources

Related reports