PEAR looted one million medical records

Have you ever wondered who stores your medical data and how they protect it?
MCBS, a medical billing company, found out the hard way.
It’s not your doctor or your hospital that processes your data: it’s an intermediary company you never meet, operating in the shadows and managing your most sensitive records.
That is exactly what MCBS does — a private company based in Georgia that handles billing and administration for dozens of healthcare providers across the United States.

Between September 22 and 26, something went seriously wrong.
During those four days, malicious actors gained unauthorized access to MCBS’s systems. The company took months to complete its investigation and did not publish an official notice until late June. By then, the scope was clear: 1,261,464 individuals had had their personal, medical, and financial information exposed. Names, dates of birth, Social Security numbers, and diagnoses — all in the wrong hands.
The ransomware group PEAR claimed responsibility for the attack.
PEAR, which stands for Pure Extraction and Ransom, claims to have exfiltrated 3.3 terabytes of data from MCBS’s systems. Beyond what the company acknowledged, the group asserts it holds human resources data, internal operations records, payment information, and emails. All of that information has already been published online, though its authenticity could not be independently verified.
More than one million people had no idea MCBS existed.

Seven healthcare providers, a single point of failure.
MCBS’s notification references seven healthcare entities whose patients may be affected, including South Georgia Radiology Consultants, SkinPath Solutions, and Radiology Associates. If you received medical care in Georgia, your information may have passed through MCBS without anyone ever telling you.
The healthcare sector accumulates breaches like no other.
This case is not an anomaly: intermediary companies that process medical data have become one of ransomware’s preferred targets because they concentrate information from thousands of patients across multiple providers. A single successful attack multiplies the damage exponentially, as has occurred in several similar incidents in recent months.

The invisible intermediary is the weakest link in the chain.
When you visit your doctor, you sign consent forms and place your trust in that practice. But your data then travels to companies you will never see or chose. If one of them fails, you bear the consequences without having had any option to protect yourself.
And the real damage may go much further.
PEAR didn’t just steal clinical records: it claims to hold financial and human resources information that could be used for identity fraud and targeted attacks. MCBS recommends placing a fraud alert and freezing your credit — two measures worth taking as soon as possible if you suspect your data was in their systems.
Exposed data that is not easily forgotten.
If you received medical services in Georgia, contact your healthcare provider to find out whether they worked with MCBS and whether your data is part of this breach.
What can you do?
- ✓Place a fraud alert with your credit bureau immediately.
- ✓Consider freezing your credit to block unauthorized account openings.
- ✓Contact your doctor to find out whether they use MCBS services.
Do you actually know who has access to your medical data right now?
Security is not improvised, it is audited. At Nacata Security we detect vulnerabilities and protect your company, because a single flaw can cost you everything you have built.
Related articles
Nacata Security, reach out to us anytime
We are Nacata Security, get to know us
web: nacata.io
email: info@nacata.io
Phone: 919930793
LinkedIn: Nacata Security
Cyberattacks that have already happened and are confirmed: hacked companies, leaked data, services down after an attack, ransoms paid.
Real cases, with names and clear consequences, explained simply so anyone understands what happened and who it affected.
RATING
10
Who are we?
At Nacata Security we are an offensive cybersecurity company specialized in audits and penetration testing.
We detect, assess and help mitigate the vulnerabilities of your systems, networks and applications before a real attacker exploits them, offering 360º defense tailored to each client.
We’d be glad to get in touch with you for whatever you need.




