Craneware Reports Data Theft Incident Affecting Healthcare Providers
US healthcare finance software provider Craneware has disclosed a cyber incident resulting in the exfiltration of file names, employee data, and customer/partner records.

Craneware, a prominent US provider of financial software for the healthcare industry, has announced a significant cybersecurity incident. The company confirmed on July 20 that unauthorized actors gained access to its data environment, leading to the theft of a substantial volume of file names.
While the majority of the exfiltrated file names are reported to be non-sensitive or publicly available regulatory data, the breach also resulted in the access and exfiltration of some employee data, alongside a subset of customer and partner records. Craneware has stated that the incident did not cause any disruption to its customer services.
In response to the breach, Craneware has proactively notified relevant authorities, including the Information Commissioner's Office in the UK and the Federal Bureau of Investigations in the US. The company is currently engaged in an ongoing investigation to identify the full scope of the incident and determine all affected parties for subsequent notification.
Details regarding the identity of the threat actors or the specific methods used to breach Craneware's defenses have not yet been disclosed. The company, which has dual headquarters in Scotland and Florida, serves approximately 2,000 hospitals and health systems across the United States with its financial and billing software solutions.
Industry experts have acknowledged Craneware's swift containment efforts but expressed concerns about the extent of data accessed. Darren Williams, CEO of BlackFog, highlighted that the large number of file names accessed indicates the ease with which determined attackers can exfiltrate data. He also pointed out the heightened risk for Craneware due to its critical position within the healthcare supply chain, a sector frequently targeted by cybercriminals.
James Neilson, SVP of Global at OPSWAT, echoed these concerns, emphasizing that Craneware's central role in the US healthcare ecosystem makes its data a prime target. Even if much of the accessed data is non-sensitive, its theft can still pose reputational and operational risks.
Williams further advised Craneware to focus on precisely identifying the full extent of the stolen data and confirming all affected individuals and entities. The incident underscores the persistent threats faced by third-party vendors in the healthcare sector, where a breach can have cascading effects on numerous patient-facing organizations.
This incident serves as a stark reminder of the vulnerabilities inherent in the digital supply chain, particularly within critical sectors like healthcare. The compromise of a vendor like Craneware, which handles sensitive financial and operational data for thousands of hospitals, highlights the need for robust security measures and continuous vigilance against evolving cyber threats.
The latest disclosure from Craneware indicates that the threat actors viewed and exfiltrated a substantial number of file names, in addition to some employee data and a selection of customer and partner records. While the company states the attack has been contained and customer-facing services remain unaffected, the investigation is ongoing to determine the full scope and sensitivity of the compromised data, which may impact entities in both the UK and US.