The Atlanta-based Medical Computer Business Services (MCBS) experienced a significant data breach last year, impacting the personal data of over 1.2 million individuals. This alarming incident highlights vulnerabilities within healthcare data management systems.
Timeline and Details of the Breach
According to a notice from MCBS, the breach occurred in September 2025 when hackers infiltrated their systems. Investigations revealed that between September 22 and September 26, unauthorized access was gained, potentially compromising sensitive personal information.
The stolen data included names, addresses, social security numbers, birth dates, health insurance details, and medical records. The breach notification specifically identified seven healthcare providers whose data was affected.
Impact on Healthcare Organizations
The breach’s extent is underscored by the US Department of Health and Human Services’ data breach tracker, which reports that 1,261,464 individuals were affected by this incident. This marks a significant breach in the security of healthcare data management systems.
The PEAR ransomware group has claimed responsibility for this attack, asserting that they accessed over 3 terabytes of data. This includes sensitive company information, client financials, human resources and business documents, vendor data, and patient PII and PHI records.
Emergence of the PEAR Ransomware Group
The PEAR ransomware group, which surfaced in mid-2025, has been linked to this and other significant cyberattacks. Their leak site lists over 100 alleged victims, indicating their aggressive approach toward data theft and distribution.
Previous cyber incidents attributed to this group include the Motility Software Solutions hack, affecting 766,000 individuals, and the Tri-Century Eye Care breach, impacting 200,000 people. The group’s activities pose a growing threat to organizations handling sensitive data.
This breach serves as a stark reminder of the importance of robust cybersecurity measures in protecting personal information. As cyberattacks become more sophisticated, organizations must prioritize enhancing their data protection strategies to safeguard against future threats.
