MCBS hack exposes 1.26 million patient records
MCBS, a medical billing company used by healthcare providers, says attackers broke into its network and may have taken files on more than 1.26 million patients.
- Report priority
- Critical
What is known
MCBS has not said how attackers first got into its network, only that they gained unauthorized access and may have copied files.
What to do
MCBS says exactly 1,261,464 people were affected by intrusion into its network between September 22 and 26, 2025, and it is notifying them directly, so check whether you or your healthcare provider used MCBS for billing and whether you receive a notice from MCBS or that provider.
Reported details
The PEAR ransomware group claims it broke into MCBS's network and stole 3.3 terabytes of files. MCBS has confirmed only that unauthorized parties accessed its systems and may have acquired files, and it has not confirmed the ransomware group's claim or the amount of data taken.
MCBS detected the intrusion while it was happening in September 2025 but took roughly eight months, finishing its investigation in late May 2026, before notifying the 1,261,464 affected individuals. Public reporting attributes the breach to the PEAR ransomware group, which claims to have exfiltrated 3.3 TB of data, but MCBS's own disclosure only confirms unauthorized network access and possible file acquisition, not a confirmed ransomware deployment or data theft volume. No technical detail on the initial access vector or exploited software has been made public.
References
- nvd.nist.gov · CVE-2026-16723 vdb entry
- github.com · GHSA-crf3-v9rr-v7hj vendor advisory
- esecurityplanet.com · minnesota-water-utilities-hit-by-coordinated-cyberattack eSecurityPlanet
- bleepingcomputer.com · hackers-target-over-30-minnesota-water-utilities-in-coordinated-ot-attack eSecurityPlanet
- mn.gov · blog eSecurityPlanet
- bleepingcomputer.com · after-the-break-in-what-attackers-do-once-theyre-already-inside BleepingComputer
- darkreading.com · ransomware-attack-japanese-frozen-food-chain DarkReading
- cert.ssi.gouv.fr · CERTFR-2026-AVI-0957 CERT-FR Advisories
- wid.cert-bund.de · securityadvisory CERT-Bund Advisories
- acn.gov.it · vulnerabilita-in-prodotti-vmware-7 ACN CSIRT Italy
- acn.gov.it · risolte-vulnerabilita-in-google-chrome-65 ACN CSIRT Italy
- acn.gov.it · nuove-vulnerabilita-in-samba-1 ACN CSIRT Italy
- sygnia.co · ransomware-incident-response Sygnia
- infosecurity-magazine.com · government-ransomware-daily Infosecurity Magazine
- github.com · Security-Advisory:-Remote-Code-Execution-in-fastjson-1.2.68–1.2.83 GitHub Advisory