1.26 Million Patients Hit As Medical Breach Exposes Social Security Info
A cyberattack on Georgia-based medical billing provider Medical Computer Business Services (MCBS) has exposed sensitive personal and health records of over 1.2 million individuals.
MCBS, an Augusta-headquartered company, which provides billing, coding, accounts receivable, and administrative services for healthcare providers, disclosed the full scale of the breach in a filing with the U.S. Department of Health and Human Services. According to the company’s statement, hackers gained access to MCBS systems between September 22 and September 26, 2025. Following a multi-month investigation only completed this late May, the firm confirmed that cybercriminals successfully compromised a vast trove of sensitive patient data.
So far, the extortion group known as PEAR (Pure Extraction and Ransom) has claimed responsibility for the intrusion, whereby they allege exfiltrating 3.3 terabytes of data from MCBS networks. Outside of PHI, PEAR claims to have stolen internal HR files, corporate financial details, payment processing records, email correspondence, and administrative databases. The group has since published the entire stolen data cache online, creating increased risks of identity theft, financial fraud, and targeted spear-phishing campaigns for those affected.
MCBS has advised potentially impacted individuals to review their medical statements, monitor their credit reports, and consider placing fraud alerts or credit freezes with major credit bureaus. Patients who received care from medical practices in Georgia are also urged to contact their healthcare providers to confirm whether their personal information was involved in the security incident.