Skip to main content
The Markets by Proactive
Go to Proactive UK
Proactive UK has moved. Growth stocks coverage continues on proactiveinvestors.com Go there →
Advertisement
The Markets
by Proactive
Proactive UK has moved.
Growth stocks coverage continues on proactiveinvestors.com
Go to Proactive UK
The Markets
by Proactive
Proactive UK has moved.
Growth stocks coverage continues on .com
Go to Proactive UK
Advertisement
The Markets
by Proactive
Proactive UK has moved.
Growth stocks coverage continues on .com
Go to Proactive UK

Tech

Craneware PLC CRW View profile

Craneware reveals cyber attack with employee and customer data stolen

Shares in Craneware PLC (AIM:CRW) fell 6% to 1,138p after it disclosed a cyber security incident in which hackers gained unauthorised access to part of its data environment and stole employee, customer and partner records.

The Edinburgh-based healthcare financial performance software firm said a significant volume of file names were viewed and taken, though its current assessment is that much of the data involved is non-sensitive or already public regulatory information.

A percentage of employee data and a subset of customer and partner records were accessed and removed, the company said.

The incident has been contained and there has been no disruption to customer services or operations.

External forensic specialists appointed by the board have confirmed there are no residual indicators of compromise in the company's systems.

Craneware has notified regulators and law enforcement agencies, including the Information Commissioner's Office in the UK and the Federal Bureau of Investigation in the US, reflecting the company's substantial American footprint.

Craneware's software is used by US hospitals and health systems to manage revenue integrity, billing compliance and pharmacy operations through its Trisus cloud platform, making data security a particularly sensitive issue for its customer base.

The company is continuing to assess the precise nature and scope of the data involved and is working with advisers to identify affected parties and prepare notifications, including any further disclosures required by regulators.

Its incident response plan was activated on discovery of the breach, with the internal IT team working alongside retained cybersecurity providers and the newly appointed external specialists.

Craneware said it will update the market as appropriate.

Broker Peel Hunt said these incidents were 'not uncommon' and the attack was certainly 'not existential'.

In a note, repeating its 'buy' call and 1,700p price target, it added: "According to the company, the incident did not involve encryption of production systems (ie not ransomware); resulted in no service downtime or SLA credits; and left no residual attacker presence.

"Management also characterised the data mix as being skewed away from PHI. Top-of-range Anthem-style scenarios are likely off the table."

The 2015 Anthem medical data breach was one of the largest healthcare cyberattacks in history, compromising the personal data of nearly 80 million individuals.

Advertisement
The Markets
by Proactive
Proactive UK has moved.
Growth stocks coverage continues on .com
Go to Proactive UK

Today’s Edition