A massive data breach has affected over 1.2 million individuals after hackers compromised the systems of Atlanta-based medical business management company MCBS (Medical Computer Business Services) in September last year. The cyberattack, carried out by the PEAR ransomware group, has exposed sensitive personal and medical information.
MCBS’s data breach notification reveals that attackers had access to its systems between September 22nd and September 26th, potentially stealing files containing names, addresses, social security numbers, dates of birth, health insurance details, and medical records. The compromised data also includes company and client financials, HR documents, partner and vendor information, patient protected health information (PHI), payment details, and emails.
The affected individuals include patients and clients of seven healthcare organizations whose data was compromised in the cyberattack. According to the US Department of Health and Human Services’ healthcare data breach tracker, the MCBS hack impacts 1,261,464 individuals. The PEAR ransomware group took credit for hacking MCBS in late September last year, claiming to have stolen over 3 terabytes worth of files.
Notably, the hackers have made available for download the information allegedly stolen from the company, raising concerns about potential identity theft and other malicious activities. The PEAR ransomware group emerged in mid-2025 and has since taken credit for several high-profile hacks, including the Motility Software Solutions breach affecting 766,000 people and the Tri-Century Eye Care breach impacting 200,000 individuals.
This incident highlights the ongoing threat of ransomware attacks on healthcare organizations and other businesses. As more sensitive data is stored online, the risk of cyberattacks continues to grow. Organizations must prioritize robust cybersecurity measures, including regular backups, strong access controls, and employee education, to prevent such breaches from occurring in the first place.
For those affected by this breach, it’s essential to remain vigilant about monitoring their financial accounts and credit reports for any suspicious activity. If you suspect your information has been compromised, report the incident to the relevant authorities and consider taking steps to protect your identity, such as placing a freeze on your credit or using an identity theft protection service. Remember, prevention is key – stay informed, stay secure.
Source: SecurityWeek — 2026-07-27