Particle.news

Craneware Confirms File-Name Exfiltration in Cyberattack

The company has notified UK and US regulators as investigators work to establish whether sensitive patient or other protected data was exposed.

Overview

  • Craneware disclosed Monday that attackers gained unauthorized access to a subset of its data environment and viewed and exfiltrated a significant volume of file names.
  • The company says a percentage of employee records and a subset of customer and partner records were accessed and taken during the breach.
  • Craneware and external specialists report the incident is contained, customer services were not disrupted, and there are currently no signs of ongoing system compromise.
  • Shares fell sharply on the disclosure, dropping as much as 8.9% in early trading, while analysts put recommendations and target prices under review.
  • The broader impact will hinge on whether sensitive US patient or other protected data is confirmed in scope, a risk that could trigger cross-border enforcement and wider commercial and reputational fallout given Craneware’s large U.S. hospital and clinic customer base.