MCBS, LLC 2025 Data Breach

MCBS LLC Healthcare Business Services Breach (2025): 6.6 Million Records Including SSN & Home Address Exposed

Company · Healthcare revenue cycle and practice management services · Medical billing, coding, accounts receivable, and administrative support provider · USA

MCBS LLC Healthcare Business Services Breach (2025): 6.6 Million Records Including SSN & Home Address Exposed

Georgia-based medical billing and practice management services firm serving healthcare providers

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
72/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Elevated
Exposed data raises the risk of fraud, targeting, and impersonation. Proactive steps are warranted.
6.6MRecords
2025Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
SSNSocial Security Number
AddressPhysical address
Classification Tags
PEARHealthcareMedicalDirect Customers2025

Breach Summary

MCBS, LLC, a Georgia-based medical billing and practice management firm, was hit by a ransomware attack carried out by the threat group PEAR in September 2025. The attack exposed approximately 6.6 million records. Because MCBS processes billing and administrative data on behalf of healthcare providers across the United States, the affected individuals are largely patients whose information was held by MCBS as part of its revenue cycle management services. The exposed data includes names, home addresses, email addresses, phone numbers, and Social Security numbers. This combination is particularly dangerous. Social Security numbers can be used to open fraudulent credit accounts, file false tax returns, and commit medical identity fraud, where an attacker uses a victim's identity to obtain healthcare services or insurance reimbursements. The healthcare context of this breach makes victims especially vulnerable to impersonation and insurance abuse, as well as phishing attempts that use accurate personal and medical details to appear credible. A class action lawsuit, Neff v. MCBS, LLC, was filed in the Southern District of Georgia in October 2025, alleging the company failed to adequately secure sensitive information. MCBS moved to dismiss the case in December 2025, arguing plaintiffs had not demonstrated actual harm. No settlement or further regulatory action had been publicly documented as of early 2026. Affected individuals should monitor their credit reports, consider placing a credit freeze with the three major bureaus, and remain alert to unsolicited contact referencing their healthcare or insurance information.

Full threat analysis, exploitation vectors, and principal guidance below.

11 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

6.6M records analyzed

About MCBS, LLC

MCBS, LLC is a Georgia-based medical billing and practice management services firm providing revenue cycle management, coding, accounts receivable, and related administrative services to healthcare providers. The company operates as a business associate under HIPAA, processing patient financial and administrative data on behalf of its provider clients. It serves a substantial number of healthcare practices and facilities across the United States.

Why They Hold Your Data

A medical billing and practice management firm like MCBS typically handles patient identity data, contact details, insurance and claims information, billing records, account balances, clinical-adjacent administrative data, and internal provider operations data as part of revenue cycle management, coding, payment processing, and compliance support workflows. Because it works on behalf of healthcare providers, its systems can also contain especially sensitive patient-linked identifiers used to process claims and manage accounts across multiple practices.

Recent Developments

MCBS, LLC does not maintain a significant public profile beyond its service offering. No major organizational changes have been prominently reported in public sources in the period prior to the 2025 breach.

Data Points Exposed

5 verified field types
Email Address
Full Name
Phone Number
Physical address High
Social Security Number Critical

Breach Impact

In September 2025 MCBS, LLC suffered a ransomware attack carried out by the PEAR group, exposing approximately 6.6 million records including names, email addresses, phone numbers, home addresses, and Social Security numbers. Because MCBS processes patient billing data on behalf of healthcare providers, the exposed records represent patient information from across its provider network rather than the company's own direct customers. A class-action lawsuit, Neff v. MCBS, LLC, was filed in October 2025 alleging cybersecurity negligence. MCBS notified affected individuals and reported the incident to regulators. No settlement or further regulatory action has been widely documented in public sources as of early 2026.

Exploitation & Downstream Threats

• Identity theft and synthetic identity construction using government-issued IDs | • SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure

Principal Risk Advisory

What this means for a principal

A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Freeze credit at all three bureaus and monitor for new-account and tax-refund fraud.
  2. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  3. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  4. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
P
Threat Actor: PEARConfidence: Low
Ambiguous alias / group

Motivation: Unknown
An ambiguous label without enough reliable public sourcing for a stable threat actor profile. It may refer to a short-lived group, handle, acronym, or non-actor entity.

Read the full threat-actor profile →

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation