Medical billing firm MCBS breach hits 1.26 million patients as PEAR ransomware claims 3TB theft

A Georgia medical billing company confirmed a ransomware attack exposed data of over 1.26 million individuals, with PEAR ransomware claiming responsibility.

MedRisk Staff
By
2 Min Read

A Georgia medical billing company has confirmed that a 2025 ransomware attack exposed the personal and health information of more than 1.26 million individuals, with the PEAR ransomware group claiming responsibility for the breach.

Medical Computer Business Services (MCBS), a regional billing and practice-management firm based in Augusta, disclosed the incident in a notification posted late last month. The company later reported to the HHS Office for Civil Rights that 1,261,464 people were affected. The breach occurred between September 22 and 26, 2025, when threat actors gained unauthorized access to the MCBS network.

The exposed data varies by individual but includes full names, Social Security numbers, dates of birth, health plan beneficiary numbers, medical history, diagnosis information, and treatment records. MCBS acts as a healthcare data aggregator, processing patient records for providers including South Georgia Radiology Consultants, SkinPath Solutions, and other covered entities.

The PEAR (Pure Extraction and Ransom) group claimed it exfiltrated 3.3 terabytes of data from MCBS systems, including HR files, business operations details, payment information, and email correspondence beyond the patient data MCBS identified. PEAR is a data theft and extortion group that does not deploy encryption ransomware, and the stolen data has been fully leaked online. MCBS urges affected individuals to place fraud alerts and consider security freezes on their credit files.

Share This Article