Attackers accessed part of Craneware’s systems and stole a significant volume of data, the healthtech company has confirmed.

Based in Scotland, Craneware provides accounting and billing software to US healthcare organisations. More than 2,000 hospitals use its services, alongside nearly 10,000 clinics and retail pharmacies.

Despite the intrusion, customer services and business operations continued without disruption. Some employee, customer, and partner records were included in the stolen data.

Attackers Accessed Craneware’s Data Environment

On 20 July, the company reported the incident in a notice to the London Stock Exchange.

Investigators found that an unauthorised party gained access to a subset of Craneware’s data environment. During the attack, the intruders viewed and exfiltrated a significant number of file names.

Most affected information consists of non-sensitive public regulatory data, according to Craneware. However, the incident also involved a percentage of employee information and some customer and partner records.

Details about the exact data types and number of exported files remain unknown.

Healthcare Links Could Create Further Risks

Stolen employee and partner data can help criminals create convincing phishing emails and social-engineering attacks.

From there, attackers may try to gain access to connected healthcare organisations. Hospitals, clinics, and pharmacies hold valuable patient, medical, and insurance information that criminal groups can use for fraud, extortion, or further attacks.

So far, Craneware has not reported any intrusion at its hospital customers.

Craneware Continues Its Investigation

External cybersecurity specialists helped the company contain the incident and investigate the attack.

Those specialists found no remaining signs of compromise in Craneware’s systems, according to the company.

Relevant regulators and law-enforcement agencies have received notification of the breach. In the UK, Craneware contacted the Information Commissioner’s Office, while the company also notified the FBI in the United States.

Work now continues to establish the full scope of the Craneware data breach, identify affected people, and issue any required notifications.


0 responses to “Craneware Data Breach Exposes Employee and Customer Records”