PEAR ransomware crew claims 1.26 million-record breach at Georgia billing firm MCBS

Medical Computer Business Services says attackers roamed its network for four days in September 2025. A ransomware group now claims it stole 3.3 terabytes of patient and business data.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Share

Key points

  • Medical Computer Business Services (MCBS), a Georgia billing company, has told U.S. regulators that a September 2025 network intrusion exposed data on 1,261,464 people.
  • The attackers were inside the network between 22 and 26 September 2025, and the internal investigation wrapped on 28 May 2026.
  • Exposed records include Social Security numbers, dates of birth, insurance IDs, diagnoses and treatment notes.
  • The PEAR ransomware group has claimed the attack and says it took 3.3 terabytes of files, which it has now leaked online.
  • Seven healthcare providers whose patients were handled by MCBS are named as affected, including South Georgia Radiology Consultants and SkinPath Solutions.

A medical billing company in Augusta, Georgia has confirmed that a break-in on its network last autumn exposed sensitive records for more than 1.2 million people.

Medical Computer Business Services, known as MCBS, filed the final tally with the U.S. Department of Health and Human Services this month: 1,261,464 individuals affected. The company had disclosed the incident in late June without giving numbers.

MCBS handles billing, coding and back-office paperwork for doctors and clinics. In practice that means it holds detailed patient files on behalf of others, a role the health privacy rules call a "business associate".

What did the hackers actually take?

A lot, and much of it is the kind of data criminals prize. MCBS says attackers had access to its systems from 22 to 26 September 2025, and forensic work finished on 28 May.

The stolen files may include full names, home addresses, Social Security numbers, dates of birth, health plan and insurance ID numbers, medical histories, diagnoses and treatment notes. Records on mental and physical conditions were also in scope. Not every person had every field exposed.

Seven healthcare providers are named in the notice as clients whose patients were caught up in the breach, including South Georgia Radiology Consultants, SkinPath Solutions, and Stephen W. Brown and Radiology Associates.

Who is PEAR ransomware?

PEAR, short for Pure Extraction and Ransom, is a newer ransomware crew, meaning a criminal group that steals data and demands payment to keep it off the internet. Some of these gangs also encrypt files, but PEAR leans on the extortion side: pay, or the data goes public.

The group has claimed MCBS on its leak site and says it exfiltrated 3.3 terabytes. Alongside the patient records MCBS listed, PEAR claims it also grabbed HR files, payment records, internal emails and business databases. First reported by BleepingComputer, the full cache has now been posted online. MCBS has not said publicly whether it received a ransom demand or refused to pay, though the leak strongly suggests no payment was made.

Should patients in Georgia worry?

Yes, and there are practical steps to take. If you have had medical care in Georgia, particularly through the providers named above, ring your doctor's office and ask whether they use MCBS.

MCBS is telling potentially affected people to put a fraud alert on their credit file, and to consider a full credit freeze, which stops anyone opening new accounts in your name.

Be wary of any phone call, text or email in the coming months that references your medical care or insurance and asks you to confirm details. Criminals with this kind of data write very convincing scam messages.

Detail Figure
People affected 1,261,464
Intrusion window 22 to 26 September 2025
Investigation completed 28 May 2026
Data claimed stolen by PEAR 3.3 terabytes
Named affected providers 7

MCBS has not disclosed how the attackers first got in. That gap matters, because the company sits at the intersection of dozens of small clinics that rely on it to handle the paperwork most patients never see.

© 2026 Threat Vectr