Craneware, a provider of healthcare financial performance solutions, has been hit by a cyber security incident.
The AIM-listed firm said it is responding to a cyber security incident involving unauthorised access to a subset of its data environment.
The company’s incident response plan has been activated, it said, including the appointment by its board of external cyber security and forensic specialists.
Their investigation is ongoing, alongside the Craneware IT team and the company’s retained cyber security service providers.
The incident has been contained and there has been no disruption to customer services or to the company’s operations, said Craneware, while the external specialists say there are no ‘residual indicators of compromise’ in its systems.
The company has notified the relevant regulators and law enforcement agencies, including the Information Commissioner’s Office in the UK and Federal Bureau of Investigations in the US.
“Investigations so far have established that a significant volume of file names were viewed and exfiltrated,” it stated. “The current assessment is that a large element of the data involved is non-sensitive or already public regulatory data.
“A percentage of Craneware employee data as well as a subset of customer and partner records have been accessed and exfiltrated.”
Dear Younger Me: The ‘2am problems’ will pass – celebrate your successes


