Craneware, a U.K.-based healthcare software company whose products are used by more than 2,000 U.S. hospitals and nearly 10,000 clinics and retail pharmacies, disclosed that attackers breached a subset of its internal data environment and exfiltrated employee, customer, and business partner information. The company said unauthorized individuals viewed and copied a significant volume of file names tied largely to non-sensitive or publicly available regulatory data, but confirmed that some sensitive corporate records were also taken.
The company said the intrusion has been contained and that the attackers no longer have access, with no disruption reported to Craneware operations or the hospital services it supports. Craneware said it activated its incident response plan, brought in external cybersecurity and forensic investigators, and notified the FBI and the U.K. Information Commissioner’s Office, while continuing to determine the full scope of the breach and whether any additional impacted data sets are involved.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Craneware said it notified the U.K. Information Commissioner’s Office and the FBI about the breach. It also engaged external cybersecurity and forensic investigators to determine the scope of the incident.
Craneware announced that unauthorized individuals breached a subset of its internal data environment and viewed and exfiltrated employee, customer, and business partner data. The company said the incident was contained and that customer services and operations were not disrupted.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcesecuritymagazine.com
Open sourcescworld.com
Open sourceitpro.com
Open sourcetherecord.media
Open sourceteiss.co.uk
Open sourcelondonstockexchange.com
Open sourcetechcrunch.com
Open sourcecyberveille.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.