Threat reportData BreachTL-2026-1716
MCBS Ransomware Data Breach: PEAR Extortion Group Exposes PII and Health Records of 1.26 Million Individuals Across Seven Healthcare Clients
MCBS Ransomware Data Breach (TL-2026-1716), also tracked as MCBS Data Breach, is a high-severity data breach, first published 2026-07-27. It is attributed to PEAR with medium confidence, affects Medical Computer Business Services (MCBS) Billing / Revenue Cycle, maps to 26 MITRE ATT&CK techniques (T1005, T1021, T1027), and is covered by 9 detection rules and 30 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 26MITRE ATT&CK
- Actors
- 2PEAR
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 30Indicators of compromise
Key facts for TL-2026-1716
- Threat ID
- TL-2026-1716
- Also known as
- MCBS Data Breach, MCBS Ransomware Incident, MCBS LLC Data Breach
- Severity
- HIGH
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- Last reviewed
- Attribution
- PEAR, Ransom
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- health, medical billing, revenue cycle management, professional services, higher education, legal, financial services, manufacturing, automotive, construction, retail and e-commerce
- Target regions
- united states of america, germany, egypt, switzerland, australia, new zealand, canada, singapore, france, jamaica
- Detection rules
- 9
- Indicators of compromise
- 30
Malware and tooling in MCBS Ransomware Data Breach
Malware and tooling: pear, AteraAgent, PowerShell, Rclone - S1040, Splashtop, WinSCP, Windows Management Instrumentation (WMI)
How MCBS Ransomware Data Breach works
Medical Computer Business Services (MCBS), an Augusta, Georgia-based HIPAA business associate providing billing and revenue-cycle-management services, suffered unauthorized network access between September 22-26, 2025, that HHS breach-portal disclosure now confirms affected 1,261,464 individuals across MCBS and seven downstream healthcare-provider clients. The PEAR ("Pure Extraction and Ransom") data-extortion group claimed responsibility on September 30, 2025, alleging theft of 3.3 TB of files including Social Security numbers, medical records, and financial data, and lists MCBS as its largest healthcare victim among 100+ claimed targets.
MCBS (Medical Computer Business Services), a regional healthcare management and revenue-cycle company founded in 1981 and headquartered at 1125 Troupe Street, Augusta, Georgia, discovered unauthorized activity within its internal network on September 25, 2025, and, working with external forensic responders, determined that an unauthorized party had access to files between September 22 and September 26, 2025. It took MCBS more than eight months — until approximately May 28, 2026 — to confirm that files containing personal and health information were subject to unauthorized acquisition. A law-firm investigation announcement followed on June 29, 2026, public consumer notification on June 26, 2026, and MCBS began mailing individual written notification letters to affected patients on July 2, 2026, with the HHS OCR breach-portal figure of 1,261,464 individuals reported in press coverage on July 27, 2026. State attorney general filings to date put the confirmed floor at 309,309 individuals (295,625 South Carolina, 13,302 Texas, 382 Massachusetts), a figure explicitly described as still rising toward the final HHS total. Exposed data includes names, addresses, dates of birth, Social Security numbers, health insurance/health-plan beneficiary and policy/subscriber identification numbers, medical history, mental and physical condition/diagnosis/treatment records, company and client financial documents, HR and business-operations records, partner/vendor data, patient payment details, and internal email communications. MCBS is offering complimentary 12-month identity-monitoring/protection services through Kroll to affected individuals. As a revenue-cycle-management vendor, MCBS's compromise directly cascades to at least seven downstream healthcare-provider clients whose patient data it processes; one of these — Stephen W. Brown & Radiology Associates of Augusta — is publicly named in notification coverage, illustrating the systemic third-party/business-associate risk inherent to medical billing outsourcing.
The PEAR group ("Pure Extraction and Ransom") claimed credit for the MCBS intrusion on its Tor data-leak site on September 30, 2025, asserting exfiltration of roughly 3.3 TB of data; MCBS has not corroborated PEAR's specific volume claim. PEAR is a data-extortion-focused actor described by researchers as being in a "formative stage, potentially testing operations or building a reputation through early attacks," employing a "low-noise, high-pressure approach, gaining access quietly before deploying encryption and extortion tactics" — though in practice its documented incidents (including MCBS) show no evidence of an encryptor payload, with extortion driven purely by threatened publication of stolen data. The group emerged fully formed in mid-2025 (first tracked 2025-08-05), posting nearly 20 victims simultaneously to a new Tor leak site, and has since claimed 100+ victims (106 per ransomware.live tracking as of July 2026, ~88.7% US-based across 11 countries including Canada, Singapore, France, and Jamaica), concentrated in professional services (36 victims), healthcare (20 victims), manufacturing (10), financial services (8), and retail/e-commerce (7), with a strong preference for organizations under $5 million in annual revenue. Roughly 15.2% of PEAR victims show associated infostealer-log overlap, and average attack-to-disclosure dwell is 21.5 days.
Initial access is consistently credential-based: reused/breached passwords, phishing, and internet-facing RDP/VPN lacking MFA — never a software exploit or disclosed CVE. Once inside, PEAR performs file-system enumeration to identify customer records, financial documents, and personnel/tax files, and maps backup configurations and EDR/security-software coverage ahead of exfiltration (Discovery). Credential access is expanded via keylogging and extraction of stored credentials from web browsers, and administrative/domain credentials are leveraged for privilege escalation and new-account creation for persistent fallback access (Persistence via registry-based autostart modifications observed per group tracking). Execution and lateral movement rely entirely on legitimate/dual-use tooling — PowerShell and Windows Management Instrumentation (WMI) for command execution and lateral traversal, AteraAgent and Splashtop RMM software for persistent remote access — never custom malware. Files are staged before bulk transfer via WinSCP and RClone to Tor-linked and cloud-storage infrastructure, with proof-of-theft samples shared with victims via third-party file-share sites (limewire[.]com, ufile[.]io) during negotiation. Defense evasion includes disabling/uninstalling antivirus and EDR agents, disabling audit/event logging, and obfuscating dropped files; PEAR also disables backups and weakens security controls to inhibit recovery before completing exfiltration. Ransom demands are calibrated to each victim's revenue using the exfiltrated financial records themselves, with strict payment deadlines, daily check-in requirements, and up to a 10% early-payment discount (documented as a 4 BTC demand in at least one case). PEAR additionally pressures victims directly by contacting employees' personal phones/accounts via Onionmail (pear@onionmail.org), Tox messenger, SMS, and WhatsApp using exfiltrated corporate directories — a notably aggressive, low-technical-barrier extortion playbook. Leak-site infrastructure runs on NGINX (version 1.22.1 observed) across two dual-mirrored .onion addresses.
MCBS is one of at least three healthcare victims PEAR claimed in September 2025 alone (alongside Tri-Century Eye Care and Western Orthopaedics), part of a broader wave that also includes the 766,670-victim Motility Software Solutions/Reynolds & Reynolds automotive-dealership-software breach (August 2025) and later 2026 claims against Monmouth University and Metropolitan Construction Systems (July 24, 2026), demonstrating an active, ongoing, cross-sector campaign rather than an isolated incident, notwithstanding a reported ~88% month-over-month drop in PEAR's attack velocity most recently. PEAR's activity rate (~8 new victim claims/month historically) and its consistent playbook of credential abuse plus living-off-the-land tooling make it a high-priority tracking target for any organization relying on third-party billing, RCM, or SaaS vendors with internet-facing remote access.
MCBS now faces at least two federal class-action lawsuits — Neff v. MCBS LLC (filed October 9, 2025) and McCollum v. MCBS LLC (filed October 14, 2025) — alleging negligent cybersecurity practices, plus at least one law-firm-announced investigation (Federman & Sherwood, June 29, 2026); MCBS has moved to dismiss the class actions.
MITRE ATT&CK techniques used in TL-2026-1716
Collection
T1005 Data from Local System; T1074 Data Staged; T1114 Email Collection
Lateral Movement
T1021 Remote Services; T1570 Lateral Tool Transfer
Defense Evasion
T1027 Obfuscated Files or Information; T1070 Indicator Removal
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service; T1567.002 Exfiltration to Cloud Storage
Credential Access
T1056.001 Keylogging; T1555.003 Credentials from Web Browsers
Execution
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1566 Phishing
Privilege Escalation
Discovery
T1083 File and Directory Discovery; T1518.001 Security Software Discovery
Persistence
T1098 Account Manipulation; T1547.001 Registry Run Keys / Startup Folder
Impact
T1490 Inhibit System Recovery; T1657 Financial Theft
Resource Development
defense-impairment
T1685 Disable or Modify Tools; T1685.005 Clear Windows Event Logs
Affected products and versions in MCBS Ransomware Data Breach
- Medical Computer Business Services (MCBS) — Billing / Revenue Cycle Management Platform and Internal Business Network
Vulnerable versions: Internal network and business systems compromised via credential abuse and internet-facing remote access — not a specific software version or CVE - Seven downstream healthcare-provider clients of MCBS, including Stephen W. Brown & Radiology Associates of Augusta — Patient billing/PHI records processed by MCBS on their behalf
Vulnerable versions: Patient data exposed indirectly via MCBS business-associate compromise
Remediation for MCBS Ransomware Data Breach
Immediate actions
- Enforce MFA on all internet-facing RDP and VPN services; disable or tightly restrict direct RDP exposure
- Force credential rotation across MCBS and all downstream healthcare-client accounts, especially any reused/previously breached passwords
- Audit for unauthorized installs of remote-management tools (AteraAgent, Splashtop) and unexpected use of WinSCP/RClone as exfiltration channels
- Review PowerShell and WMI execution logs for anomalous lateral-movement activity and disable unneeded WMI remoting
- Verify backup integrity and immutability; confirm backups cannot be disabled or deleted by a compromised administrative account
- Notify and coordinate breach response with all seven identified downstream healthcare-provider clients whose patient data transited MCBS systems, including Stephen W. Brown & Radiology Associates of Augusta
- Hunt for credential-harvesting activity (keylogging, browser credential-store extraction) and unauthorized registry Run-key/autostart persistence entries across the environment
- Confirm complimentary 12-month Kroll identity-monitoring enrollment is available and communicated to all confirmed affected individuals
Longer-term hardening
- Adopt zero-trust remote access (no direct internet-facing RDP/VPN without MFA and conditional access)
- Deploy EDR/behavioral detection tuned to flag living-off-the-land abuse of legitimate RMM and file-transfer tools
- Establish a formal third-party/business-associate risk management program with security assessments of RCM and billing vendors
- Network-segment billing-vendor systems from client-facing production/patient-record systems
- Employee security awareness training covering personal-device extortion contact attempts (SMS/WhatsApp/Tox/Onionmail) from threat actors using stolen corporate directories
- Offer credit monitoring / identity-theft protection proactively to all affected individuals given SSN and PHI exposure
- Harden browser credential storage (enterprise password manager, disable browser-saved passwords) to blunt PEAR's browser-credential-theft TTP
Weaknesses (CWE) in MCBS Ransomware Data Breach
Timeline of MCBS Ransomware Data Breach
- PEAR (Pure Extraction and Ransom) emerges fully formed, posting nearly 20 victims simultaneously to a new Tor data-leak site.
- PEAR first discovered/tracked by ransomware-monitoring services (ransomware.live).
- Motility Software Solutions (subsidiary of Reynolds & Reynolds) discovers unauthorized server access later claimed by PEAR, affecting 766,670 individuals.
- Tri-Century Eye Care detects suspicious network activity, later confirmed as a PEAR-claimed breach affecting ~200,000 individuals.
- Tri-Century Eye Care confirms unauthorized access to patient and employee files.
- Unauthorized access to MCBS's internal network begins.
- MCBS discovers unauthorized network activity and launches a forensic investigation with external cybersecurity experts.
- Window of unauthorized access to MCBS files closes, per MCBS's own disclosure.
- PEAR claims responsibility for the MCBS breach on its Tor leak site, alleging 3.3 TB of exfiltrated data; PEAR also claims a September breach at Western Orthopaedics.
- First federal class action, Neff v. MCBS LLC, filed alleging negligent cybersecurity practices.
- Second federal class action, McCollum v. MCBS LLC, filed.
- MCBS's forensic investigation confirms files containing personal and health information were subject to unauthorized acquisition — over eight months after the intrusion.
- MCBS issues public consumer breach notification.
- Law firm Federman & Sherwood publicly announces an investigation into the MCBS data breach on behalf of affected individuals.
- MCBS begins mailing individual written notification letters to affected patients, including patients of downstream client Stephen W. Brown & Radiology Associates of Augusta, and offers complimentary 12-month identity monitoring through Kroll.
- PEAR claims its most recent victim, Metropolitan Construction Systems, evidencing a continued, active extortion campaign.
- Press coverage (SecurityWeek) reports the HHS OCR breach-portal figure of 1,261,464 individuals affected by the MCBS breach.
Sources cited for MCBS Ransomware Data Breach
- MCBS Data Breach Affects 1.2 Million Individuals
- Medical billing firm MCBS warns 300,000+ patients of data breach
- MCBS, LLC Data Breach Investigation
- PEAR Threat Group Profile
- PEAR | BlackFog Cybersecurity Glossary
- Ransomware.live: pear group tracking
- 766,000 Impacted by Data Breach at Dealership Software Provider Motility
- Auto dealership software company notifies 767,000 people of data breach claimed by ransomware gang
- Tri-Century Eye Care & Pittsburgh Gastroenterology Associates Announce Data Breaches
- Data incident prompts notices to patients of local radiology associate
- MCBS, LLC and Stephen W. Brown & Radiology Associates of Augusta: Data incident prompts notices to patients
- MCBS, LLC Data Breach – Investigated by Federman & Sherwood
Detection coverage for TL-2026-1716
As of 2026-07-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1716 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.