CSIDB logo
Incident

Medical Computer Business Services

Incident posture

Attack window
Sep 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-07 16:26

Linked entities

Victim
Medical Computer Business Services
Threat actors
1 actor
Sources
4 sources

Timeline

Occurred
Sep 2025
Discovered
Undetermined
Disclosed
Jun 2026
Resolved
Pending

Summary

Medical Computer Business Services experienced a data breach that exposed personal and health information of over 1.26 million individuals. Unauthorized actors gained access to the company's network and exfiltrated approximately 3.3 terabytes of data, which the PEAR ransomware group claimed responsibility for and later leaked online. The compromised data included names, addresses, Social Security numbers, dates of birth, health insurance details, medical histories, and other protected health information. The breach was identified through an internal investigation and subsequently reported to regulators and the public. No specific technical indicators of the attack have been published, limiting detailed technical attribution.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

Medical Computer Business Services (MCBS), a healthcare billing and practice‑management company based in Augusta, Georgia, reported that unauthorized access to its network servers occurred between September 22 and September 26, 2025. The intrusion was first disclosed publicly in late June 2026 after an internal investigation concluded on May 28, 2026. MCBS filed a formal breach notification with the U.S. Department of Health and Human Services Office for Civil Rights on June 26, 2026 and posted a notice on its website later that month, with media coverage beginning on July 28, 2026. The company said it engaged a cybersecurity firm to assist with the investigation and to determine the scope of the data that may have been taken.

The breach affected 1,261,464 individuals, according to the HHS OCR breach portal. Exposed information included full names, physical addresses, Social Security numbers, dates of birth, health plan beneficiary numbers, health insurance policy numbers, subscriber identification numbers, medical histories, mental and physical condition details, medical treatment information, and diagnosis information. MCBS also noted that the PEAR ransomware group claimed responsibility for the attack, alleging the exfiltration of 3.3 terabytes of data that included human resources records, business operation details, payment information, email correspondence, and various databases. BleepingComputer reported a screenshot from the dark web showing the data trove available for download, indicating that the ransom was likely not paid. MCBS stated it had no evidence of identity theft linked to the breach at the time of notification but urged affected individuals to monitor their credit histories.

In its response, MCBS said it worked with a cybersecurity firm to investigate the incident and to learn more about what data was accessed or removed. The company noted that its servers contain information from several HIPAA‑covered provider clients, including C&C MD PC, Nuclear Medicine and Pathology Associates, Radiation Oncology Associates, SkinPath Solutions, South Georgia Radiology Consultants, Stephen W. Brown & Radiology Associates of Augusta, and Vascular Radiology Associates, all of which were listed as impacted. MCBS emphasized that it continually evaluates and modifies its practices to enhance the security and privacy of the personal information it maintains. The notification also mentioned that the PEAR ransomware group emerged in mid‑2025 and has claimed responsibility for other incidents affecting hundreds of thousands of individuals.

Sources

Sources available to members: 4 sources.

CSIDB