MCBS Ransomware Data Breach: PEAR Extortion Group Exposes PII and Health Records of 1.26 Million Individuals Across Seven Healthcare Clients — Threadlinqs Intelligence
As of 2026-07-27, MCBS Ransomware Data Breach: PEAR Extortion Group Exposes PII and Health Records of 1.26 Million Individuals Across Seven Healthcare Clients is a high-severity data breach threat attributed to PEAR (Pure Extraction, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-1716 · Severity: HIGH · Status: ACTIVE · Category: DATA_BREACH
Attribution: PEAR (Pure Extraction · FINANCIAL
Medical Computer Business Services (MCBS), an Augusta, Georgia-based HIPAA business associate providing billing and revenue-cycle-management services, suffered unauthorized network access between
MCBS (Medical Computer Business Services), a regional healthcare management and revenue-cycle company founded in 1981 and headquartered at 1125 Troupe Street, Augusta, Georgia, discovered unauthorized activity within its internal network on September 25, 2025, and, working with external forensic responders, determined that an unauthorized party had access to files between September 22 and September 26, 2025. It took MCBS more than eight months — until approximately May 28, 2026 — to confirm that files containing personal and health information were subject to unauthorized acquisition. A law-firm investigation announcement followed on June 29, 2026, public consumer notification on June 26, 2026, and MCBS began mailing individual written notification letters to affected patients on July 2, 2026, with the HHS OCR breach-portal figure of 1,261,464 individuals reported in press coverage on July 27, 2026. State attorney general filings to date put the confirmed floor at 309,309 individuals (295,625 South Carolina, 13,302 Texas, 382 Massachusetts), a figure explicitly described as still rising toward the final HHS total. Exposed data includes names, addresses, dates of birth, Social Security numbers, health insurance/health-plan beneficiary and policy/subscriber identification numbers, medical history, mental and physical condition/diagnosis/treatment records, company and client financial documents, HR and business-operations records, partner/vendor data, patient payment details, and internal email communications. MCBS is offering complimentary 12-month identity-monitoring/protection services through Kroll to affected individuals. As a revenue-cycle-management vendor, MCBS's compromise directly cascades to at least seven downstream healthcare-provider clients whose patient data it processes; one of these — Stephen W. Brown & Radiology Associates of Augusta — is publicly named in notification coverage, illustrating the systemic third-party/business-associate risk inherent to medical billing outsourcing.
The PEAR group ("Pure Extraction and Ransom") claimed credit for the MCBS intrusion on its Tor data-leak site on September 30, 2025, asserting exfiltration of roughly 3.3 TB of data; MCBS has not corroborated PEAR's specific volume claim. PEAR is a data-extortion-focused actor described by researchers as being in a "formative stage, potentially testing operations or building a reputation through early attacks," employing a "low-noise, high-pressure approach, gaining access quietly before deploying encryption and extortion tactics" — though in practice its documented incidents (including MCBS) show no evidence of an encryptor payload, with extortion driven purely by threatened publication of stolen data. The group emerged fully formed in mid-2025 (first tracked 2025-08-05), posting nearly 20 victims simultaneously to a new Tor leak site, and has since claimed 100+ victims (106 per ransomware.live tracking as of July 2026, ~88.7% US-based across 11 countries including Canada, Singapore, France, and Jamaica), concentrated in professional services (36 victims), healthcare (20 victims), manufacturing (10), financial services (8), and retail/e-commerce (7), with a strong preference for organizations under $5 million in annual revenue. Roughly 15.2% of PEAR victims show associated infostealer-log overlap, and average attack-to-disclosure dwell is 21.5 days.
Initial access is consistently credential-based: reused/breached passwords, phishing, and internet-facing RDP/VPN lacking MFA — never a software exploit or disclosed CVE. Once inside, PEAR performs file-system enumeration to identify customer records, financial documents, and personnel/tax files, and maps backup configurations and EDR/security-software coverage ahead of exfiltration (Discovery). Credential access is expanded via keylogging and extraction of stored credentials from web browsers, and administrative/domain credentials are leveraged for privilege escalation and new-account c
Weaknesses (CWE)
CWE-522, CWE-287
Target sectors: health, medical billing, revenue cycle management, professional services, higher education, legal, financial services, manufacturing, automotive, construction, retail and e-commerce
Target regions: united states of america, germany, egypt, switzerland, australia, new zealand, canada, singapore, france, jamaica
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
DATA_BREACH, HIGH, threat intelligence, cybersecurity, T1078, T1566, T1133, T1059.001, T1098, T1547.001, T1078.002, T1562, T1562.001, T1070