MCBS medical data stolen in ransomware attack

Published July 27, 2026

MCBS, an Atlanta medical billing company, had files stolen by the PEAR ransomware group. The stolen data included names, Social Security numbers, and medical and insurance information on 1.2 million people.

Report priority
High
Involves
Medical Computer Business Services
Group
MCBS medical data stolen in

What is known

Attackers linked to the PEAR ransomware group got into MCBS's network and had access for about four days in September 2025, copying company and patient files before the intrusion was discovered.

What to do

If you were a patient of one of the seven healthcare organizations named in MCBS's breach notification, which covers people whose data MCBS processed between September 22 and 26, 2025, check MCBS's posted notice or any breach letter you receive to see if you're on the list.

Monitor your accounts for unusual activity and consider placing fraud alerts on your credit reports through the three major bureaus (Equifax, Experian, TransUnion).

Reported details

PEAR breaks into MCBS's network in September 2025 and has access for several days. The group copies more than 3 TB of files, including patient names, Social Security numbers, health insurance details, and medical records tied to MCBS's healthcare clients. When MCBS does not pay, PEAR posts the stolen files on its leak site for anyone to download.

PEAR is a ransomware and data-extortion group that emerged in mid-2025 and has listed more than 100 alleged victims on its leak site, including Motility Software Solutions (766,000 people) and Tri-Century Eye Care (200,000 people). For MCBS, PEAR claims roughly 3 TB taken, covering company financials, HR records, vendor data, patient PII/PHI, payment details, and emails. The US Department of Health and Human Services breach tracker lists the confirmed total as 1,261,464 individuals.