Data breach at medical billing firm MCBS affects 1.26 million people

110 Views

Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people.

Commenting, Deborah Galea Senior Manager at Filigran, said:

“PEAR is a clear signal of where extortion is heading: attackers no longer need to encrypt a single file to bring an organisation to its knees. Instead, they steal sensitive data and use a drip-feed leak site to apply sustained pressure, releasing victim files in increments until payment is made.

“Active since mid-2025 and according to threat intelligence sources still generating fresh victim disclosures as recently as this month, PEAR relies on legitimate tools like Atera, Splashtop, and Rclone rather than custom malware, proving that stealth, not destruction, is becoming the new ransomware playbook.

“For healthcare, finance, and consulting organisations in the US especially, this means defenses have to shift from spotting malware to spotting behavior: MFA, anomalous account activity, and unauthorized remote-access tools are now the front line.”