# MCBS Ransomware Data Breach: PEAR Extortion Group Exposes PII and Health Records of 1.26 Million Individuals Across Seven Healthcare Clients

> Medical Computer Business Services (MCBS), an Augusta, Georgia-based HIPAA business associate providing billing and revenue-cycle-management services, suffered unauthorized network access between September 22-26, 2025, that HHS breach-portal disclosure now confirms affected 1,261,464 individuals across MCBS and seven downstream healthcare-provider clients. The PEAR ("Pure Extraction and Ransom") data-extortion group claimed responsibility on September 30, 2025, alleging theft of 3.3 TB of files including Social Security numbers, medical records, and financial data, and lists MCBS as its largest healthcare victim among 100+ claimed targets.

- **Published:** 2026-07-27T00:00:00Z
- **Last reviewed:** 2026-07-27T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1716
- **ID:** TL-2026-1716
- **Severity:** HIGH
- **Category:** DATA_BREACH
- **Status:** ACTIVE
- **Actor:** PEAR
- **Detections:** 9 · **IOCs:** 30 (full data via the Threadlinqs MCP server — Purple tier)

## Description

MCBS (Medical Computer Business Services), a regional healthcare management and revenue-cycle company founded in 1981 and headquartered at 1125 Troupe Street, Augusta, Georgia, discovered unauthorized activity within its internal network on September 25, 2025, and, working with external forensic responders, determined that an unauthorized party had access to files between September 22 and September 26, 2025. It took MCBS more than eight months — until approximately May 28, 2026 — to confirm that files containing personal and health information were subject to unauthorized acquisition. A law-firm investigation announcement followed on June 29, 2026, public consumer notification on June 26, 2026, and MCBS began mailing individual written notification letters to affected patients on July 2, 2026, with the HHS OCR breach-portal figure of 1,261,464 individuals reported in press coverage on July 27, 2026. State attorney general filings to date put the confirmed floor at 309,309 individuals (295,625 South Carolina, 13,302 Texas, 382 Massachusetts), a figure explicitly described as still rising toward the final HHS total. Exposed data includes names, addresses, dates of birth, Social Security numbers, health insurance/health-plan beneficiary and policy/subscriber identification numbers, medical history, mental and physical condition/diagnosis/treatment records, company and client financial documents, HR and business-operations records, partner/vendor data, patient payment details, and internal email communications. MCBS is offering complimentary 12-month identity-monitoring/protection services through Kroll to affected individuals. As a revenue-cycle-management vendor, MCBS's compromise directly cascades to at least seven downstream healthcare-provider clients whose patient data it processes; one of these — Stephen W. Brown & Radiology Associates of Augusta — is publicly named in notification coverage, illustrating the systemic third-party/business-associate risk inherent to medical billing outsourcing.

The PEAR group ("Pure Extraction and Ransom") claimed credit for the MCBS intrusion on its Tor data-leak site on September 30, 2025, asserting exfiltration of roughly 3.3 TB of data; MCBS has not corroborated PEAR's specific volume claim. PEAR is a data-extortion-focused actor described by researchers as being in a "formative stage, potentially testing operations or building a reputation through early attacks," employing a "low-noise, high-pressure approach, gaining access quietly before deploying encryption and extortion tactics" — though in practice its documented incidents (including MCBS) show no evidence of an encryptor payload, with extortion driven purely by threatened publication of stolen data. The group emerged fully formed in mid-2025 (first tracked 2025-08-05), posting nearly 20 victims simultaneously to a new Tor leak site, and has since claimed 100+ victims (106 per ransomware.live tracking as of July 2026, ~88.7% US-based across 11 countries including Canada, Singapore, France, and Jamaica), concentrated in professional services (36 victims), healthcare (20 victims), manufacturing (10), financial services (8), and retail/e-commerce (7), with a strong preference for organizations under $5 million in annual revenue. Roughly 15.2% of PEAR victims show associated infostealer-log overlap, and average attack-to-disclosure dwell is 21.5 days.

Initial access is consistently credential-based: reused/breached passwords, phishing, and internet-facing RDP/VPN lacking MFA — never a software exploit or disclosed CVE. Once inside, PEAR performs file-system enumeration to identify customer records, financial documents, and personnel/tax files, and maps backup configurations and EDR/security-software coverage ahead of exfiltration (Discovery). Credential access is expanded via keylogging and extraction of stored credentials from web browsers, and administrative/domain credentials are leveraged for privilege escalation and new-account creation for persistent fallback access (Persistence via registry-based autostart modifications observed per group tracking). Execution and lateral movement rely entirely on legitimate/dual-use tooling — PowerShell and Windows Management Instrumentation (WMI) for command execution and lateral traversal, AteraAgent and Splashtop RMM software for persistent remote access — never custom malware. Files are staged before bulk transfer via WinSCP and RClone to Tor-linked and cloud-storage infrastructure, with proof-of-theft samples shared with victims via third-party file-share sites (limewire[.]com, ufile[.]io) during negotiation. Defense evasion includes disabling/uninstalling antivirus and EDR agents, disabling audit/event logging, and obfuscating dropped files; PEAR also disables backups and weakens security controls to inhibit recovery before completing exfiltration. Ransom demands are calibrated to each victim's revenue using the exfiltrated financial records themselves, with strict payment deadlines, daily check-in requirements, and up to a 10% early-payment discount (documented as a 4 BTC demand in at least one case). PEAR additionally pressures victims directly by contacting employees' personal phones/accounts via Onionmail (pear@onionmail.org), Tox messenger, SMS, and WhatsApp using exfiltrated corporate directories — a notably aggressive, low-technical-barrier extortion playbook. Leak-site infrastructure runs on NGINX (version 1.22.1 observed) across two dual-mirrored .onion addresses.

MCBS is one of at least three healthcare victims PEAR claimed in September 2025 alone (alongside Tri-Century Eye Care and Western Orthopaedics), part of a broader wave that also includes the 766,670-victim Motility Software Solutions/Reynolds & Reynolds automotive-dealership-software breach (August 2025) and later 2026 claims against Monmouth University and Metropolitan Construction Systems (July 24, 2026), demonstrating an active, ongoing, cross-sector campaign rather than an isolated incident, notwithstanding a reported ~88% month-over-month drop in PEAR's attack velocity most recently. PEAR's activity rate (~8 new victim claims/month historically) and its consistent playbook of credential abuse plus living-off-the-land tooling make it a high-priority tracking target for any organization relying on third-party billing, RCM, or SaaS vendors with internet-facing remote access.

MCBS now faces at least two federal class-action lawsuits — Neff v. MCBS LLC (filed October 9, 2025) and McCollum v. MCBS LLC (filed October 14, 2025) — alleging negligent cybersecurity practices, plus at least one law-firm-announced investigation (Federman & Sherwood, June 29, 2026); MCBS has moved to dismiss the class actions.

## MITRE ATT&CK

- T1078 Valid Accounts
- T1566 Phishing
- T1133 External Remote Services
- T1059.001 PowerShell
- T1098 Account Manipulation
- T1547.001 Registry Run Keys / Startup Folder
- T1078.002 Domain Accounts
- T1685 Disable or Modify Tools
- T1070 Indicator Removal
- T1685.005 Clear Windows Event Logs
- T1027 Obfuscated Files or Information
- T1056.001 Keylogging
- T1555.003 Credentials from Web Browsers
- T1083 File and Directory Discovery
- T1518.001 Security Software Discovery
- T1021 Remote Services
- T1570 Lateral Tool Transfer
- T1005 Data from Local System
- T1114 Email Collection
- T1074 Data Staged
- T1567 Exfiltration Over Web Service
- T1567.002 Exfiltration to Cloud Storage
- T1041 Exfiltration Over C2 Channel
- T1490 Inhibit System Recovery
- T1657 Financial Theft
- T1583.001 Domains

## Sources

- [MCBS Data Breach Affects 1.2 Million Individuals](https://www.securityweek.com/mcbs-data-breach-affects-1-2-million-individuals/)
- [Medical billing firm MCBS warns 300,000+ patients of data breach](https://www.comparitech.com/news/medical-billing-firm-mcbs-warns-300000-patients-of-data-breach/)
- [MCBS, LLC Data Breach Investigation](https://www.almeidalawgroup.com/data-breach-news/mcbs-llc-data-breach-investigation/)
- [PEAR Threat Group Profile](https://www.halcyon.ai/threat-group/pear)
- [PEAR | BlackFog Cybersecurity Glossary](https://www.blackfog.com/cybersecurity-101/pear/)
- [Ransomware.live: pear group tracking](https://www.ransomware.live/group/pear)
- [766,000 Impacted by Data Breach at Dealership Software Provider Motility](https://www.securityweek.com/766000-impacted-by-data-breach-at-dealership-software-provider-motility/)
- [Auto dealership software company notifies 767,000 people of data breach claimed by ransomware gang](https://www.comparitech.com/news/auto-dealership-software-company-notifies-767000-people-of-data-breach-claimed-by-ransomware-gang/)
- [Tri-Century Eye Care & Pittsburgh Gastroenterology Associates Announce Data Breaches](https://www.hipaajournal.com/tri-century-eye-care-pittsburgh-gastroenterology-associates-data-breaches/)
- [Data incident prompts notices to patients of local radiology associate](https://www.wrdw.com/2026/07/02/data-incident-prompts-notices-patients-local-radiology-associate/)
- [MCBS, LLC and Stephen W. Brown & Radiology Associates of Augusta: Data incident prompts notices to patients](https://blog.rankiteo.com/mcbbro1783038262-mcbs-llc-stephen-w-brown-radiology-associates-of-augusta-breach-july-2026/)
- [MCBS, LLC Data Breach – Investigated by Federman & Sherwood](https://www.federmanlaw.com/blog/mcbs-llc-data-breach-investigated-by-federman-sherwood/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1716
