MCBS Data Breach Affects 1.2 Million Individuals

A massive data breach affecting over 1.2 million individuals has come to light in a cyberattack on Atlanta-based medical business management company MCBS, also known as Medical Computer Business Services. The incident occurred last September and was carried out by the PEAR ransomware group, which claims to have stolen more than 3 terabytes of sensitive data from the company.

According to an investigation, hackers gained access to MCBS’s systems between September 22 and September 26, potentially stealing files that contained personal information such as names, addresses, Social Security numbers, dates of birth, health insurance details, and medical records. Seven healthcare organizations were also affected by this cyberattack, with the total number of individuals impacted standing at 1,261,464.

The PEAR ransomware group, which emerged in mid-2025, has taken credit for several high-profile hacks, including the Motility Software Solutions breach, affecting 766,000 people, and the Tri-Century Eye Care breach, impacting 200,000 individuals. The group’s leak website currently lists over 100 alleged victims.

What makes this incident particularly concerning is that hackers have made available for download the information allegedly stolen from MCBS. This not only puts affected individuals at risk of identity theft but also compromises sensitive business and financial data belonging to both the company and its clients. As a result, it’s essential for those impacted by this breach to take immediate action to protect themselves.

The investigation into the incident has shed light on the vulnerabilities in MCBS’s systems that allowed hackers to gain access. While the exact details of these vulnerabilities are not publicly disclosed, it highlights the need for robust cybersecurity measures and regular security audits to prevent such incidents from occurring in the future.

The increasing number of data breaches affecting healthcare organizations is a pressing concern, given the sensitive nature of patient information involved. It’s essential that those responsible for managing these systems take adequate steps to protect against cyber threats and ensure that patient data remains secure.

In conclusion, this breach serves as a stark reminder of the importance of robust cybersecurity measures in today’s digital age. Affected individuals should remain vigilant and take immediate action to protect themselves from potential identity theft or financial loss. Companies and organizations must also prioritize their cybersecurity defenses to prevent similar incidents from occurring in the future.


Source: SecurityWeek — 2026-07-27