Threat reportData BreachTL-2026-1716

MCBS Ransomware Data Breach: PEAR Extortion Group Exposes PII and Health Records of 1.26 Million Individuals Across Seven Healthcare Clients

highACTIVE

MCBS Ransomware Data Breach (TL-2026-1716), also tracked as MCBS Data Breach, is a high-severity data breach, first published 2026-07-27. It is attributed to PEAR with medium confidence, affects Medical Computer Business Services (MCBS) Billing / Revenue Cycle, maps to 26 MITRE ATT&CK techniques (T1005, T1021, T1027), and is covered by 9 detection rules and 30 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
26MITRE ATT&CK
Actors
2PEAR
Detection rules
9SPL · KQL · Sigma
IOCs
30Indicators of compromise

Key facts for TL-2026-1716

Threat ID
TL-2026-1716
Also known as
MCBS Data Breach, MCBS Ransomware Incident, MCBS LLC Data Breach
Severity
HIGH
Status
ACTIVE
Category
DATA_BREACH
First published
Last reviewed
Attribution
PEAR, Ransom
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
health, medical billing, revenue cycle management, professional services, higher education, legal, financial services, manufacturing, automotive, construction, retail and e-commerce
Target regions
united states of america, germany, egypt, switzerland, australia, new zealand, canada, singapore, france, jamaica
Detection rules
9
Indicators of compromise
30

Malware and tooling in MCBS Ransomware Data Breach

Malware and tooling: pear, AteraAgent, PowerShell, Rclone - S1040, Splashtop, WinSCP, Windows Management Instrumentation (WMI)

How MCBS Ransomware Data Breach works

Medical Computer Business Services (MCBS), an Augusta, Georgia-based HIPAA business associate providing billing and revenue-cycle-management services, suffered unauthorized network access between September 22-26, 2025, that HHS breach-portal disclosure now confirms affected 1,261,464 individuals across MCBS and seven downstream healthcare-provider clients. The PEAR ("Pure Extraction and Ransom") data-extortion group claimed responsibility on September 30, 2025, alleging theft of 3.3 TB of files including Social Security numbers, medical records, and financial data, and lists MCBS as its largest healthcare victim among 100+ claimed targets.

MCBS (Medical Computer Business Services), a regional healthcare management and revenue-cycle company founded in 1981 and headquartered at 1125 Troupe Street, Augusta, Georgia, discovered unauthorized activity within its internal network on September 25, 2025, and, working with external forensic responders, determined that an unauthorized party had access to files between September 22 and September 26, 2025. It took MCBS more than eight months — until approximately May 28, 2026 — to confirm that files containing personal and health information were subject to unauthorized acquisition. A law-firm investigation announcement followed on June 29, 2026, public consumer notification on June 26, 2026, and MCBS began mailing individual written notification letters to affected patients on July 2, 2026, with the HHS OCR breach-portal figure of 1,261,464 individuals reported in press coverage on July 27, 2026. State attorney general filings to date put the confirmed floor at 309,309 individuals (295,625 South Carolina, 13,302 Texas, 382 Massachusetts), a figure explicitly described as still rising toward the final HHS total. Exposed data includes names, addresses, dates of birth, Social Security numbers, health insurance/health-plan beneficiary and policy/subscriber identification numbers, medical history, mental and physical condition/diagnosis/treatment records, company and client financial documents, HR and business-operations records, partner/vendor data, patient payment details, and internal email communications. MCBS is offering complimentary 12-month identity-monitoring/protection services through Kroll to affected individuals. As a revenue-cycle-management vendor, MCBS's compromise directly cascades to at least seven downstream healthcare-provider clients whose patient data it processes; one of these — Stephen W. Brown & Radiology Associates of Augusta — is publicly named in notification coverage, illustrating the systemic third-party/business-associate risk inherent to medical billing outsourcing.

The PEAR group ("Pure Extraction and Ransom") claimed credit for the MCBS intrusion on its Tor data-leak site on September 30, 2025, asserting exfiltration of roughly 3.3 TB of data; MCBS has not corroborated PEAR's specific volume claim. PEAR is a data-extortion-focused actor described by researchers as being in a "formative stage, potentially testing operations or building a reputation through early attacks," employing a "low-noise, high-pressure approach, gaining access quietly before deploying encryption and extortion tactics" — though in practice its documented incidents (including MCBS) show no evidence of an encryptor payload, with extortion driven purely by threatened publication of stolen data. The group emerged fully formed in mid-2025 (first tracked 2025-08-05), posting nearly 20 victims simultaneously to a new Tor leak site, and has since claimed 100+ victims (106 per ransomware.live tracking as of July 2026, ~88.7% US-based across 11 countries including Canada, Singapore, France, and Jamaica), concentrated in professional services (36 victims), healthcare (20 victims), manufacturing (10), financial services (8), and retail/e-commerce (7), with a strong preference for organizations under $5 million in annual revenue. Roughly 15.2% of PEAR victims show associated infostealer-log overlap, and average attack-to-disclosure dwell is 21.5 days.

Initial access is consistently credential-based: reused/breached passwords, phishing, and internet-facing RDP/VPN lacking MFA — never a software exploit or disclosed CVE. Once inside, PEAR performs file-system enumeration to identify customer records, financial documents, and personnel/tax files, and maps backup configurations and EDR/security-software coverage ahead of exfiltration (Discovery). Credential access is expanded via keylogging and extraction of stored credentials from web browsers, and administrative/domain credentials are leveraged for privilege escalation and new-account creation for persistent fallback access (Persistence via registry-based autostart modifications observed per group tracking). Execution and lateral movement rely entirely on legitimate/dual-use tooling — PowerShell and Windows Management Instrumentation (WMI) for command execution and lateral traversal, AteraAgent and Splashtop RMM software for persistent remote access — never custom malware. Files are staged before bulk transfer via WinSCP and RClone to Tor-linked and cloud-storage infrastructure, with proof-of-theft samples shared with victims via third-party file-share sites (limewire[.]com, ufile[.]io) during negotiation. Defense evasion includes disabling/uninstalling antivirus and EDR agents, disabling audit/event logging, and obfuscating dropped files; PEAR also disables backups and weakens security controls to inhibit recovery before completing exfiltration. Ransom demands are calibrated to each victim's revenue using the exfiltrated financial records themselves, with strict payment deadlines, daily check-in requirements, and up to a 10% early-payment discount (documented as a 4 BTC demand in at least one case). PEAR additionally pressures victims directly by contacting employees' personal phones/accounts via Onionmail (pear@onionmail.org), Tox messenger, SMS, and WhatsApp using exfiltrated corporate directories — a notably aggressive, low-technical-barrier extortion playbook. Leak-site infrastructure runs on NGINX (version 1.22.1 observed) across two dual-mirrored .onion addresses.

MCBS is one of at least three healthcare victims PEAR claimed in September 2025 alone (alongside Tri-Century Eye Care and Western Orthopaedics), part of a broader wave that also includes the 766,670-victim Motility Software Solutions/Reynolds & Reynolds automotive-dealership-software breach (August 2025) and later 2026 claims against Monmouth University and Metropolitan Construction Systems (July 24, 2026), demonstrating an active, ongoing, cross-sector campaign rather than an isolated incident, notwithstanding a reported ~88% month-over-month drop in PEAR's attack velocity most recently. PEAR's activity rate (~8 new victim claims/month historically) and its consistent playbook of credential abuse plus living-off-the-land tooling make it a high-priority tracking target for any organization relying on third-party billing, RCM, or SaaS vendors with internet-facing remote access.

MCBS now faces at least two federal class-action lawsuits — Neff v. MCBS LLC (filed October 9, 2025) and McCollum v. MCBS LLC (filed October 14, 2025) — alleging negligent cybersecurity practices, plus at least one law-firm-announced investigation (Federman & Sherwood, June 29, 2026); MCBS has moved to dismiss the class actions.

MITRE ATT&CK techniques used in TL-2026-1716

Collection

T1005 Data from Local System; T1074 Data Staged; T1114 Email Collection

Lateral Movement

T1021 Remote Services; T1570 Lateral Tool Transfer

Defense Evasion

T1027 Obfuscated Files or Information; T1070 Indicator Removal

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service; T1567.002 Exfiltration to Cloud Storage

Credential Access

T1056.001 Keylogging; T1555.003 Credentials from Web Browsers

Execution

T1059.001 PowerShell

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1566 Phishing

Privilege Escalation

T1078.002 Domain Accounts

Discovery

T1083 File and Directory Discovery; T1518.001 Security Software Discovery

Persistence

T1098 Account Manipulation; T1547.001 Registry Run Keys / Startup Folder

Impact

T1490 Inhibit System Recovery; T1657 Financial Theft

Resource Development

T1583.001 Domains

defense-impairment

T1685 Disable or Modify Tools; T1685.005 Clear Windows Event Logs

Affected products and versions in MCBS Ransomware Data Breach

  • Medical Computer Business Services (MCBS) — Billing / Revenue Cycle Management Platform and Internal Business Network
    Vulnerable versions: Internal network and business systems compromised via credential abuse and internet-facing remote access — not a specific software version or CVE
  • Seven downstream healthcare-provider clients of MCBS, including Stephen W. Brown & Radiology Associates of Augusta — Patient billing/PHI records processed by MCBS on their behalf
    Vulnerable versions: Patient data exposed indirectly via MCBS business-associate compromise

Remediation for MCBS Ransomware Data Breach

Immediate actions

  • Enforce MFA on all internet-facing RDP and VPN services; disable or tightly restrict direct RDP exposure
  • Force credential rotation across MCBS and all downstream healthcare-client accounts, especially any reused/previously breached passwords
  • Audit for unauthorized installs of remote-management tools (AteraAgent, Splashtop) and unexpected use of WinSCP/RClone as exfiltration channels
  • Review PowerShell and WMI execution logs for anomalous lateral-movement activity and disable unneeded WMI remoting
  • Verify backup integrity and immutability; confirm backups cannot be disabled or deleted by a compromised administrative account
  • Notify and coordinate breach response with all seven identified downstream healthcare-provider clients whose patient data transited MCBS systems, including Stephen W. Brown & Radiology Associates of Augusta
  • Hunt for credential-harvesting activity (keylogging, browser credential-store extraction) and unauthorized registry Run-key/autostart persistence entries across the environment
  • Confirm complimentary 12-month Kroll identity-monitoring enrollment is available and communicated to all confirmed affected individuals

Longer-term hardening

  • Adopt zero-trust remote access (no direct internet-facing RDP/VPN without MFA and conditional access)
  • Deploy EDR/behavioral detection tuned to flag living-off-the-land abuse of legitimate RMM and file-transfer tools
  • Establish a formal third-party/business-associate risk management program with security assessments of RCM and billing vendors
  • Network-segment billing-vendor systems from client-facing production/patient-record systems
  • Employee security awareness training covering personal-device extortion contact attempts (SMS/WhatsApp/Tox/Onionmail) from threat actors using stolen corporate directories
  • Offer credit monitoring / identity-theft protection proactively to all affected individuals given SSN and PHI exposure
  • Harden browser credential storage (enterprise password manager, disable browser-saved passwords) to blunt PEAR's browser-credential-theft TTP

Weaknesses (CWE) in MCBS Ransomware Data Breach

CWE-522, CWE-287

Timeline of MCBS Ransomware Data Breach

  • PEAR (Pure Extraction and Ransom) emerges fully formed, posting nearly 20 victims simultaneously to a new Tor data-leak site.
  • PEAR first discovered/tracked by ransomware-monitoring services (ransomware.live).
  • Motility Software Solutions (subsidiary of Reynolds & Reynolds) discovers unauthorized server access later claimed by PEAR, affecting 766,670 individuals.
  • Tri-Century Eye Care detects suspicious network activity, later confirmed as a PEAR-claimed breach affecting ~200,000 individuals.
  • Tri-Century Eye Care confirms unauthorized access to patient and employee files.
  • Unauthorized access to MCBS's internal network begins.
  • MCBS discovers unauthorized network activity and launches a forensic investigation with external cybersecurity experts.
  • Window of unauthorized access to MCBS files closes, per MCBS's own disclosure.
  • PEAR claims responsibility for the MCBS breach on its Tor leak site, alleging 3.3 TB of exfiltrated data; PEAR also claims a September breach at Western Orthopaedics.
  • First federal class action, Neff v. MCBS LLC, filed alleging negligent cybersecurity practices.
  • Second federal class action, McCollum v. MCBS LLC, filed.
  • MCBS's forensic investigation confirms files containing personal and health information were subject to unauthorized acquisition — over eight months after the intrusion.
  • MCBS issues public consumer breach notification.
  • Law firm Federman & Sherwood publicly announces an investigation into the MCBS data breach on behalf of affected individuals.
  • MCBS begins mailing individual written notification letters to affected patients, including patients of downstream client Stephen W. Brown & Radiology Associates of Augusta, and offers complimentary 12-month identity monitoring through Kroll.
  • PEAR claims its most recent victim, Metropolitan Construction Systems, evidencing a continued, active extortion campaign.
  • Press coverage (SecurityWeek) reports the HHS OCR breach-portal figure of 1,261,464 individuals affected by the MCBS breach.

Sources cited for MCBS Ransomware Data Breach

Detection coverage for TL-2026-1716

As of 2026-07-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1716 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
30 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats