Menu
Browse

Cyber Incident Victim: Medical Computer Business Services

Date:

Sep 2025

Location:

United States of America

Summary

Medical Computer Business Services experienced a cyber intrusion that exposed personal and health information of over 1.2 million individuals. The compromised data included names, addresses, Social Security numbers, dates of birth, health insurance details, and medical records belonging to seven healthcare organizations. Attackers, identifying themselves as the PEAR ransomware group, claimed to have taken more than three terabytes of files, encompassing financial, human resources, vendor, patient, and email data, and made the material available for download. The group has also taken credit for additional breaches affecting hundreds of thousands of people and maintains a leak site listing over one hundred alleged victims.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

In September 2025, attackers targeted the Atlanta‑based medical business management company Medical Computer Business Services (MCBS). According to MCBS’s data breach notification, the intrusion occurred between September 22 and September 26, during which the threat actors gained access to the company’s systems. The PEAR ransomware group later claimed responsibility for the attack, stating that they had exfiltrated more than three terabytes of data. The compromised files reportedly included company and client financials, human resources and business operations documents, partner and vendor data, patient personally identifiable information and protected health information, payment details, and internal emails.

Cyber Incident Image

The breach exposed personal information such as names, addresses, Social Security numbers, dates of birth, health insurance details, and medical records for more than 1.2 million individuals. MCBS’s notification identified seven healthcare organizations whose data was involved in the incident. The U.S. Department of Health and Human Services’ healthcare breach tracker records the MCBS incident as affecting 1,261,464 individuals. PEAR’s leak site, which emerged in mid‑2025, lists over one hundred alleged victims, including the Motility Software Solutions compromise that impacted 766,000 people and the Tri‑Century Eye Care breach that affected 200,000 individuals.

MCBS responded by posting a data breach notification on its website and conducting an investigation that confirmed the attackers’ access window. The notification detailed the types of data potentially stolen and listed the affected healthcare partners. The PEAR group made the allegedly stolen information available for download on their leak site. No further details about containment, remediation, or regulatory actions are provided in the source material.

Sources
Sources available to members
1 source