MCBS, LLC Listed by pear Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
MCBS, LLC was listed by the pear ransomware group on September 25, 2025, after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may be affected; individuals should check whether their information was exposed and take appropriate steps.
Ransomware groups continue to target organizations that sit at the intersection of business operations and sensitive personal data, particularly those supporting healthcare. In this environment, even service providers that do not deliver clinical care directly can become high-value targets because of the records and systems they manage. On September 25, 2025, MCBS, LLC was listed by the ransomware group known as pear, which claimed to have exfiltrated internal files during an attack. The number of people affected remains unknown, and public detail about the precise scope is limited. The listing matters because organizations that supply management services to healthcare providers often hold operational, financial, and personal information that can affect both the companies they serve and the individuals whose data those companies process.
What is known so far rests on the group’s public claim and the limited summary available: MCBS, LLC provides a complete range of management services to healthcare providers, and the attackers assert that internal files were taken. No independent confirmation of the volume of data, the exact systems involved, or the full timeline has been released in the available record. For people whose information may have been held by MCBS or its clients, the incident underscores the ongoing risk that ransomware operations pose to the broader healthcare support ecosystem.
Inside the incident
According to the available record, MCBS, LLC was listed by the pear ransomware group on September 25, 2025. The group claims that internal files were exfiltrated as part of a ransomware attack. Public reporting does not disclose the date the intrusion began, how long the attackers remained inside the environment, which systems were accessed, or whether encryption was also deployed against production systems. The number of people affected is unknown. No dollar amounts, file counts, or sample data sets have been detailed in the facts provided. The only concrete assertion is that internal files were taken and that the organization was named on the group’s leak site. Beyond that listing and the description of the data as internal files from a ransomware incident, further technical or operational specifics remain undisclosed.
The group behind it: pear
Pear is a ransomware group that, like many of its peers, has been observed listing victim organizations on dedicated leak sites after claiming to have stolen data. Such groups typically follow a double-extortion model: they gain access, exfiltrate material, and then threaten to publish or sell it if a ransom is not paid. Public reporting on pear and similar actors indicates they often target mid-sized organizations across multiple sectors, including those with connections to healthcare and professional services, because those environments can contain both operationally critical files and regulated personal information. The group’s listing of MCBS, LLC should be treated as an unverified claim unless and until independent confirmation is available. No statements attributed to pear specifically about this victim—beyond the fact of the listing and the assertion of internal-file exfiltration—appear in the provided facts, and none should be invented.
About MCBS, LLC
MCBS, LLC is described as providing a complete range of management services to healthcare providers. Organizations of this type commonly handle administrative, financial, operational, and compliance-related functions for clinics, practices, or other care-delivery entities. They may process or store business records, contracts, billing information, employee data, and, in some cases, information that originates from patient or provider interactions. Because healthcare-adjacent service firms sit close to regulated data flows, a breach involving them can have consequences that extend beyond the firm itself to the providers it supports and the individuals those providers serve. The exact size of MCBS, LLC, its client list, and the precise systems it operates are not detailed in the public facts of this incident; what is clear is that its role places it in a sector where data sensitivity and operational continuity are both high priorities.
The information in question
The facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of file types, categories of personal data, or volumes has been disclosed. For an organization that supplies management services to healthcare providers, internal files could in principle include business records, correspondence, financial documents, employee information, or materials related to client operations. Whether any of those categories actually appear in the material claimed by pear is unconfirmed. It is therefore not possible to state as fact that specific data elements—such as names, addresses, medical identifiers, or payment details—were exposed. The exact contents remain unconfirmed, and any assessment of impact must rest on that limitation.
What's at stake
For individuals whose information may have been present in the exfiltrated files, the primary risks are the usual consequences of unauthorized access to personal or financial records: potential misuse for fraud, social engineering, or identity-related crimes. Because the organization serves healthcare providers, there is also the possibility that client-related operational data could be involved, which might create secondary effects for those providers and the people they care for. For MCBS, LLC itself, the stakes include operational disruption, the cost of investigation and remediation, potential regulatory scrutiny depending on the nature of any regulated data involved, and reputational harm with clients who rely on it for management services. None of these outcomes is confirmed by the limited public record; they represent the concrete risks that typically accompany ransomware claims of this kind when internal files are said to have been taken.
If your data was in this claimed breach
If you believe your information may have been held by MCBS, LLC or by a healthcare provider that uses its services, begin with basic precautions: monitor financial and credit accounts for unusual activity, enable multi-factor authentication on important online accounts, and be alert to phishing or social-engineering attempts that reference healthcare or administrative services. Consider placing a fraud alert or credit freeze if you have reason to think sensitive personal identifiers were involved. Because the exact data types and the number of people affected remain unknown, treat any notification you receive from the organization or from a client of the organization as the authoritative source for next steps. Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets, which can help determine whether additional monitoring is warranted.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Iroquois Memorial Hospital Listed by pear Ransomware GroupMedical Center, LLP Listed by pear Ransomware GroupWestern Orthopaedics Listed by pear Ransomware GroupBrevard Skin Listed by pear Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the MCBS, LLC Listed by pear Ransomware Group →
Publicly posted by pear — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.