Skip to main content
Emerging ThreatsData Breaches

Craneware Discloses Data Theft in Cyber Incident

Rows of file cabinets and servers in a brightly-lit data storage area with scattered papers on a nearby table.

“The significant number of file names being accessed and copied shows that determined attackers can carry out data exfiltration with relative ease. The exposure of customer and business partner records, along with public regulatory data, demonstrates that even incidents framed as low severity can carry real exposure risk.” — Darren Williams, CEO and Founder, BlackFog

Craneware confirms unauthorized access to its data environment

Healthcare finance software provider Craneware disclosed on July 20 that it had identified a cybersecurity incident involving unauthorized access to parts of its data environment. The company said a “significant volume” of file names were viewed and exfiltrated. While Craneware reported no disruption to customer services, it acknowledged that some employee data and a subset of customer and partner records were also accessed and taken.

Scale and nature of the files: largely non-sensitive but not harmless

Craneware described a large element of the exfiltrated file names as non-sensitive data or already public regulatory data. The firm nonetheless admitted that employee records and some customer and partner records were part of what was accessed. No further specifics on the number or categories of personal records were provided in the company notice.

Response steps: containment, notifications, and ongoing investigation

The company said it contained the incident quickly and is continuing its response. Craneware has notified regulators in both jurisdictions where it operates: the Information Commissioner’s Office in the UK and the Federal Bureau of Investigation in the US. The firm is working to identify the affected parties so that it can notify them directly. Craneware did not disclose the identity of the intruders or how they gained access to its systems.

Expert reaction from BlackFog and OPSWAT

Cybersecurity experts publicly commended Craneware for a fast containment effort while flagging concern about the breadth of accessed data. Darren Williams of anti-data exfiltration provider BlackFog warned that the scale of file-name access shows how readily determined attackers can exfiltrate data, and stressed that incidents described as “low severity” can still carry exposure risk. James Neilson, SVP of Global at OPSWAT, emphasized that Craneware’s widespread use across the US healthcare system makes the data it holds an attractive target for cybercriminals, noting the company “sits at the centre of the US healthcare ecosystem” supporting thousands of healthcare organisations.

What this means for hospitals, security teams, and regulators

  • Hospitals and health systems that use Craneware tools: Many of Craneware’s customers are in the US healthcare system — the company partners with around 2,000 hospitals and health systems. Those customers will need to track Craneware’s notifications and confirm whether any of their records were among the subset accessed.
  • Security teams and technology vendors: Practitioners will likely review the scope of what was exposed and press for a forensic accounting of files taken; as Darren Williams put it, Craneware must “determine the full scope of what was taken and confirm who's affected.”
  • Regulators in the UK and US: The Information Commissioner’s Office and the FBI have been notified. Their involvement creates an official channel for inquiry and, where applicable, compliance action or further investigation.

Craneware’s role as a supplier of accounting and billing software — including the Trisus Chargemaster, which lists billable items, procedures and services — places the company inside the healthcare supply chain that attackers increasingly seek to exploit. The company’s public notice leaves two concrete next steps on the table: completing its internal review to identify precisely what was taken, and notifying affected employees, customers and partners. Absent disclosure of how access occurred or who was responsible, those immediate answers remain outstanding.

Original report — Infosecurity Magazine