CRANEWARE , a healthcare finance software provider, has reported a cyber incident involving unauthorized access to its data environment, resulting in the theft of numerous file names and some employee and customer data. Although most stolen data was reportedly non-sensitive or public, the breach poses a significant risk due to Craneware's central role in the US healthcare ecosystem, which services approximately 2000 hospitals.
The company promptly notified the UK's Information Commissioner's Office and the FBI while continuing to investigate the incident. Experts have expressed concern over the ease with which attackers executed the data exfiltration.