PrivacySignal
Breach

Data breach at medical billing firm MCBS affects 1.26 million people

BleepingComputer · · International · Data Breaches

Medical Computer Business Services (MCBS), a healthcare billing company, has disclosed a 2025 network breach that exposed sensitive information belonging to more than 1.26 million people. The company has not yet detailed what specific data was compromised or how long attackers had access.

Why this matters: Medical billing firms sit at a quiet intersection of your health history and your financial life. They hold diagnoses, insurance details, and payment records — information people never chose to share with a billing contractor but had no real option to refuse. Most of the 1.26 million people affected probably had no idea MCBS existed before this breach. That is the problem. When sensitive data flows through third-party processors you never interact with, you lose any practical ability to protect it. Someone else made the security decisions. You absorb the consequences.

Who should care: Cybersecurity · Privacy officers · Administrators

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
BleepingComputer · · International

Florida confirms DMV database breached via stolen police account

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

TX: Two Lamesa ISD employees arrested over security breach

Two employees of Lamesa Independent School District in Texas were arrested following a law enforcement investigation into alleged computer security breaches. The Lamesa Police Department, working with the Texas Rangers, made the arrests after the district issued a public statement about the incident.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →
Breach
BleepingComputer · · International

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
DataBreaches.net · · International

Ukrainian National Sentenced to Four Years in Prison for Wire Fraud Conspiracy in Connection with Conti Ransomware

There’s an update to a previously reported case. From the Department of Justice, this press release: Oleksii Oleksiyovych Lytvynenko, 44, a Ukrainian national, was sentenced today to four years in prison for conspiracy to commit wire fraud in connection with a conspiracy to deploy Conti, a ransomware variant that infected the computers of more than 1,000... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →