Skip to main content
Security

Data breach at medical billing firm MCBS affects 1.26 million people

Data breach at medical billing firm MCBS affects 1.26 million people Image: Primary
Medical billing company Medical Computer Business Services disclosed Tuesday that a 2025 network breach exposed the sensitive information of 1,261,464 people. The Augusta, Georgia-based firm reported the figure in a disclosure to the U.S. Department of Health and Human Services. MCBS published a notification on its website in late June informing that threat actors gained unauthorized access to its network between Sept. 22 and 26, 2025. The company completed an investigation on May 28 determining that data including full names, Social Security numbers, dates of birth, health insurance details, and medical history may have been exposed. The notice lists seven covered entities, including South Georgia Radiology Consultants and SkinPath Solutions, whose patient data MCBS handled as a business associate. The PEAR ransomware group has claimed responsibility for the attack, alleging it exfiltrated 3.3 terabytes of data that has since been leaked online. MCBS urges potentially affected individuals to place a fraud alert and consider a security freeze on their credit file.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Bleeping Computer, SecurityWeek and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security Policy
Security Policy

Florida confirms DMV driver database breach via stolen police credentials

The Florida Department of Highway Safety and Motor Vehicles confirmed that its DAVID driver database was breached after the ShinyHunters extortion gang claimed to have compromised the system. The agency said it learned of the bre...

Security
Security

Wiz reports Artifactory flaw chain exploited to plant Rust backdoor

Wiz says multiple threat actors chained two JFrog Artifactory vulnerabilities, CVE-2026-42018 and CVE-2026-42016, against self-hosted servers between August 15 and September 8, 2026, obtaining an internal anonymous-user JWT and ex...

Security Infrastructure
Security Infrastructure

GitLab patches maximum-severity file-read flaw as probes hit exposed servers

GitLab released patches for a maximum-severity path traversal flaw in its repository commits API that lets an unauthenticated attacker read arbitrary files from a GitLab server under certain conditions, the company said. The vuln...

Products Security
Products Security

Figma launches Japan data residency for enterprise file hosting

Figma introduced data residency in Japan, letting enterprise customers store Figma Design, FigJam, Figma Slides, and Figma Make file data in the country. The company said the option responds to customer demand for domestic storag...