CRANEWARE SUFFERS DATA BREACH AFFECTING HOSPITALS AND STAFF
Craneware, an Edinburgh-based healthcare technology company listed on London's Alternative Investment Market, has disclosed a cyber attack in which customer and employee data were stolen. The firm supplies accounting and billing software to approximately 2,000 hospitals and health systems and 10,000 clinics and pharmacies across the United States through its cloud platform Trisus. A significant volume of file names were viewed and exfiltrated during the breach, though the company assessed that a large portion of the accessed data comprised non-sensitive or already publicly available regulatory information.
The attack resulted in unauthorised access to some Craneware employee data and a subset of customer and partner records. The company stated that the incident has been contained and has not disrupted customer services or its operations, with no evidence of system compromise according to the business and external specialists engaged to assess the breach. Craneware employs approximately 800 people globally and notified the Information Commissioner's Office in the UK and the Federal Bureau of Investigations in the US. The firm is working with advisers to establish the precise scope of data involved and determine whether further disclosure to authorities is required.
Cyber attacks have affected several major British businesses in recent months, including Jaguar Land Rover, Marks & Spencer and Harrods. Craneware's disclosure comes as UK companies across multiple sectors face heightened security risks from such incidents.