Data breach at medical billing firm MCBS affects 1.26 million people
Medical billing and practice-management provider Medical Computer Business Services (MCBS) has disclosed that a cyberattack affecting its network between September 22 and 26, 2025, exposed sensitive data belonging to 1,261,464 individuals. The compromised information may include names, addresses, Social Security numbers, dates of birth, health insurance details, and medical records such as diagnoses, treatment information, and health conditions.
MCBS, which processes patient data on behalf of several healthcare organizations, completed its investigation in May 2026 and has advised affected individuals to monitor their accounts, place fraud alerts, and consider credit freezes. The PEAR ransomware group has claimed responsibility for the attack and alleged that it stole 3.3TB of data during the breach.
Coca-Cola confirms data theft in Fairlife ransomware attack
Coca-Cola has confirmed that a ransomware attack against its dairy subsidiary, Fairlife, resulted in the theft of company data and a temporary disruption to production at its U.S. facilities. The attack, claimed by the Anubis ransomware group, forced Fairlife to suspend operations while response and recovery efforts were underway, although most production has now resumed and product availability was largely maintained through existing inventory.
The threat actors allege they stole around 1TB of confidential data and later published the files after ransom demands were not met. While Coca-Cola acknowledged that “certain data” was taken by an unauthorized third party, it has not disclosed the specific data involved and currently believes the incident is unlikely to have a material impact on its financial performance.
Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack
A coordinated cyberattack targeting operational technology (OT) systems disrupted more than 30 community water and wastewater utilities across Minnesota on July 26 and 27, prompting a statewide cybersecurity response. Several communities, including Braham, Plymouth, South St. Paul, and Maple Plain, reported outages, communication failures, or disruptions to automated controls, forcing some facilities to switch to manual operations while maintaining safe water services.
Minnesota IT Services (MNIT) is working alongside the FBI, CISA, EPA, and other partners to investigate the incident, share threat intelligence, and support recovery efforts. While the attacker’s identity remains unknown, officials have described the activity as coordinated due to similarities in timing, access methods, and targeted infrastructure, highlighting the growing cyber threat facing critical infrastructure and industrial control systems
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
Security researchers have identified more than 24,000 internet-exposed Baseboard Management Controllers (BMCs) that leak password-derived authentication hashes due to CVE-2013-4786, a long-standing weakness in the IPMI 2.0 protocol introduced in 2004. The flaw allows attackers to obtain authentication data without valid credentials and perform offline password-cracking attacks, bypassing account lockouts and security monitoring.
Researchers found that over 30% of the exposed systems used weak or predictable passwords, including factory-issued credentials that could be recovered using common wordlists and known password patterns. Because BMCs provide low-level, out-of-band control of physical servers, successful compromise could enable attackers to manipulate firmware, maintain persistent access, and gain extensive control over critical infrastructure, including data centre and AI environments.
Analyst Insight
These incidents demonstrate the broad range of risks facing organisations across healthcare, manufacturing, critical infrastructure, and data centre environments. The MCBS breach highlights the continued attractiveness of healthcare data to cybercriminals, with large volumes of sensitive personal and medical information presenting significant opportunities for fraud and identity theft.
Meanwhile, the ransomware attack against Fairlife shows how threat actors are increasingly willing to target operational processes as well as corporate data, creating business disruption alongside extortion pressure. The coordinated attacks against Minnesota water utilities further underline the growing focus on operational technology (OT) and critical infrastructure, where even temporary disruptions can have widespread public impact.
Finally, the discovery of thousands of internet-exposed BMCs vulnerable to password hash leakage demonstrates how longstanding security weaknesses and poor exposure management can leave critical systems vulnerable to compromise. Collectively, these incidents reinforce the importance of strong access controls, network segmentation, proactive vulnerability management, continuous monitoring, and robust incident response capabilities to reduce both the likelihood and impact of modern cyber threats.
Protect your organization: If you’re concerned about this vulnerability or need immediate security assessments, our team is available 24/7 for incident response support. Contact us today.
