MCBS Data Breach: 1.2 Million Affected by PEAR Ransomware

Unverified PEAR ransomware claim of MCBS breach impacting 1.2 million

The MCBS data breach has come to light after the PEAR ransomware group claimed responsibility for stealing a massive 3 TB of data. The breach reportedly affects 1.2 million individuals, making it one of the most significant healthcare supply chain incidents in recent months. This event highlights the persistent threat posed by ransomware groups to healthcare-related organisations and their service providers.

PEAR Ransomware Group Claims Massive MCBS Data Theft

On 13 March 2026, the PEAR ransomware group publicly announced that it had compromised the systems of MCBS, a medical business management firm. According to their claims, they exfiltrated 3 TB of data, which includes sensitive information impacting approximately 1.2 million individuals. The group has yet to provide detailed samples of the data or proof of life, but their announcement has raised significant concern across the healthcare sector.

MCBS, based in the United States, provides billing, revenue cycle management and other administrative services to a broad range of healthcare providers. As a third-party business associate, MCBS handles large volumes of medical and personal data, making it an attractive target for ransomware groups seeking financial gain or leverage.

  • Date of Claim: 13 March 2026
  • Threat Actor: PEAR ransomware group
  • Data Volume: 3 TB
  • Individuals Impacted: 1.2 million
  • Status: Claims unconfirmed, no public data leak yet

Timeline and Current Exploitation Status

The earliest indicator of compromise surfaced when the PEAR ransomware group posted about the MCBS breach on its dark web leak site. The group has a history of targeting healthcare and supply chain entities, often threatening to publicly release sensitive data if ransom demands are not met.

As of this writing, MCBS has not confirmed the breach nor provided details about the potential compromise. There are no reports of the group having released data samples or proof of stolen records, and no public indicators of compromise have been published. However, ransomware groups often use the threat of exposure to force negotiations.

  • 13 March 2026: PEAR group claims MCBS breach on leak site
  • 14–18 March 2026: No confirmation or denial from MCBS; no public data leak detected
  • Ongoing: Healthcare sector monitoring for indicators or further threat activity

The lack of confirmation from MCBS means that the scope and nature of the compromised data remain speculative. However, given the company’s role in handling patient billing and administrative data, the exposed information could include names, addresses, dates of birth, medical records, insurance details and financial account data.

How the Attack May Have Unfolded

While technical details are scarce due to the absence of a public incident report, the PEAR ransomware group’s modus operandi typically involves exploiting vulnerabilities in remote access systems, email phishing campaigns or leveraging supply chain weaknesses. Once initial access is gained, attackers move laterally, escalate privileges and exfiltrate large volumes of data before deploying ransomware to encrypt critical files.

Healthcare supply chain and business associates like MCBS are frequent targets because:

  • They aggregate sensitive data from multiple providers
  • Security controls may lag behind primary healthcare institutions
  • Disruption can impact clinical and financial operations, increasing ransom pressure

The PEAR group is known for its focus on data theft for extortion, rather than immediate deployment of ransomware encryption. This allows them to negotiate ransoms based on the threat of public data exposure, a tactic that has proven lucrative in past attacks targeting healthcare supply chains.

Why This MCBS Data Breach Matters

The MCBS data breach, if confirmed, could have significant consequences for affected individuals and healthcare providers. Exposure of medical and financial data increases the risk of identity theft, fraud and regulatory penalties. For healthcare organisations, reliance on third-party business associates introduces additional risk, as breaches through partners can have cascading effects across the sector.

Immediate Steps for Organisations

  • Monitor official MCBS communications and threat intelligence feeds for breach confirmation and indicators of compromise
  • Assess exposure by reviewing your organisation’s relationship with MCBS and third-party data flows
  • Prepare response plans in case affected individuals or systems are identified

Organisations should remain vigilant for any signs of data misuse or follow-on phishing campaigns targeting patients or staff, particularly if downstream data is leaked or sold.

Originally reported by securityweek.com.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call