Data breach at medical billing firm at MCBS

Information:

   Medical Computer Business Services (MCBS) is a private company based in Georgia, USA, that specializes in providing medical billing and practice management services to healthcare organizations. Acting as a healthcare data aggregator, MCBS handles back-office operations for various hospitals and specialty clinics, such as radiology and pathology practices. Their comprehensive services include medical billing and coding for insurance claims, accounts receivable management, and handling administrative and financial tasks related to patient records. By managing these complex financial and administrative processes, MCBS helps healthcare providers reduce their paperwork burden, allowing them to focus entirely on patient care.

Incident :

  Between September 22 and 26, 2025, unauthorized actors gained access to the firm’s network. After an extensive forensic investigation that concluded in late May 2026, the company confirmed that sensitive personal and health information including names, addresses, Social Security numbers, health insurance details, and medical histories had been compromised. Because MCBS acts as a third-party administrative vendor for various healthcare providers, such as radiology and pathology clinics, many of the affected patients likely had no direct relationship with or knowledge of the company.

  The PEAR ransomware group has claimed responsibility for the cyberattack. Unlike traditional ransomware that focuses on encrypting files, PEAR’s primary tactic is data theft and extortion. The group claims to have exfiltrated 3.3 terabytes of data from MCBS. Beyond the patient records acknowledged by the company, the hackers assert they have also stolen internal HR documents, payment information, business operations data, and emails, which they claim to have already leaked online.

  MCBS began notifying affected individuals and the U.S. Department of Health and Human Services in late June 2026. The company is urging those potentially impacted to monitor their financial accounts, place fraud alerts, and consider instituting credit freezes to protect themselves against identity theft. This breach highlights a growing cybersecurity vulnerability in the healthcare sector, where intermediary back-office vendors become prime targets due to the vast amounts of sensitive data they aggregate from multiple providers.

Recommendation :

  Access Control & Segmentation: To minimize third-party vendor risks, enforce the principle of least privilege. Segment external vendor networks away from your core internal databases to prevent attackers from using them as a stepping stone for lateral movement.SIEM

  Monitoring & Analysis: Since this threat group focuses on stealing data rather than encrypting it, configuring alerts on your SIEM (like QRadar or Splunk) is crucial. Correlate security events (such as endpoint activity) with network flows (traffic volume) to detect abnormal spikes in outbound bandwidth, especially outside of standard business hours.

  Threat Hunting: Focus on anomalous Identity and Access Management (IAM) activity, such as suspicious privilege escalation attempts or unusual MFA prompt fatigue. Additionally, monitor outbound traffic for connections sending data to unauthorized external cloud storage services.

The important things is Security systems. We must concern and monitor as usual.
For more information please contact
Email :sales@inetms.co.th
065 149 2822 (Ms.Suphatson )
063 204 4534 (Ms.Atsamaphorn)
065 929 6330 (Ms.Kansinee)
092 257 6902 (Ms.Narusorn)
063 197 7510 (Mr.Yanotai)
065 725 7405 (Ms.Nattharini)

References :

Weekly Interesting CVE

NO.

CVE Name

Published Date

Last Update

Device/Appplication/OS Target

Attack Type

CVSS
Severity Rating

Detail

Solution

Reference

1

CVE-2026-60530

21/7/2026

21/7/2026

Oracle
Http Server
affected at 14.1.2.0.0

Local Privilege Escalation

7.8

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_http2.so). The supported version that is affected is 14.1.2.0.0. HTTP Server.

Update to the latest version.

https://www.cve.org/CVERecord?id=CVE-2026-60530

2

CVE-2026-15682

13/7/2026

13/7/2026

AnyDesk
affected at 9.0.4

OS Command Injection

3.3

A flaw in AnyDesk's Send Support Information feature allows local attackers with low-privileged code execution to create arbitrary files via junctions, leading to a denial-of-service (DoS) condition. (ZDI-CAN-26645)

Update to the latest version.

https://www.cve.org/CVERecord?id=CVE-2026-15682

3

CVE-2026-58630

24/7/2026

27/7/2026

Microsoft
Azure App Service Linux

Access control

10

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

If using Azure Stack Hub, update to the latest patch version.

https://www.cve.org/CVERecord?id=CVE-2026-58630

 4

CVE-2026-16414

21/7/2026

21/7/2026

Google
Chrome
affected from 150.0.7871.182 before 150.0.7871.182

Sandbox

7.8

Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic.

Update to the latest version.

https://www.cve.org/CVERecord?id=CVE-2026-16414

5

CVE-2026-16756

23/7/2026

23/7/2026

AWS
aws-smithy-http-server
affected from 0 through 0.66.4

Resource consumption

9.9

Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks.

Upgrade to version 0.66.5 or later.

https://www.cve.org/CVERecord?id=CVE-2026-16756

 

Malware News or Campaign IOC/IOA | EN

No

Campaign Name

Detection Date

Attack

Type

 

Description

 

Mitigation/Remediation

1

msaRAT Malware Uses Chrome and Edge as C2 Communication Channels to Evade Detection

24/07/2026

Malware

The newly identified msaRAT backdoor malware has been observed being used by the Chaos Ransomware group to control Google Chrome or Microsoft Edge and use the browser as a relay for communication with its Command-and-Control (C2) server, rather than allowing the malware to communicate directly. As a result, the generated network traffic closely resembles legitimate web browsing activity, making it more difficult for security solutions to detect.

The attack typically begins by tricking users into installing Remote Management Software (RMS). The attackers then download an MSI installer disguised as a legitimate Windows system update to load msaRAT into memory. Once executed, the malware establishes a covert communication channel with the C2 server, enabling the attackers to maintain remote access and control while evading detection.

  • Keep your browser and operating system up to date with the latest versions.
  • Download software exclusively from trusted and official sources.
  • Conduct security awareness training for employees to help them recognize and prevent cyber threats.

Ref: https://www.theregister.com/cyber-crime/2026/07/07/cai-cloud-worm-gives-competitors-malware-the-boot-then-steals-secrets-and-mines-for-coin/5267856 

05 August 2026

Viewed 60 time

Engine by shopup.com