Breach

Craneware confirms customer and employee data exposed in security incident

(Adobe Stock)

Scottish health tech company Craneware has confirmed that customer and employee data was exposed following a security incident. The company stated that its incident response plan was activated, and external cybersecurity and forensic specialists were appointed to investigate the breach, based on information published by IT Pro.

The breach, which occurred on July 20, saw a significant volume of file names viewed and exfiltrated by unauthorized individuals. While the company noted these files were not sensitive and were publicly available, a subset of customer and partner records, along with employee data, was also accessed and exfiltrated. Craneware has notified regulators, including the UK Information Commissioner’s Office (ICO), and law enforcement agencies like the FBI.

As a provider of accounting and billing software to approximately 2,000 US hospitals, Craneware is considered a prime target, offering cybercriminals a potential pathway into the healthcare supply chain. Experts warn that even seemingly low-risk stolen data can be used for phishing and social engineering attacks, urging employees, customers, and partners to remain vigilant against unsolicited communications and suspicious activity.

Source: IT Pro

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Attack Vector

You can skip this ad in 5 seconds