Craneware Confirms File-Name Exfiltration in Cyberattack
The company has notified UK and US regulators as investigators work to establish whether sensitive patient or other protected data was exposed.
Overview
- Craneware disclosed Monday that attackers gained unauthorized access to a subset of its data environment and viewed and exfiltrated a significant volume of file names.
- The company says a percentage of employee records and a subset of customer and partner records were accessed and taken during the breach.
- Craneware and external specialists report the incident is contained, customer services were not disrupted, and there are currently no signs of ongoing system compromise.
- Shares fell sharply on the disclosure, dropping as much as 8.9% in early trading, while analysts put recommendations and target prices under review.
- The broader impact will hinge on whether sensitive US patient or other protected data is confirmed in scope, a risk that could trigger cross-border enforcement and wider commercial and reputational fallout given Craneware’s large U.S. hospital and clinic customer base.