Craneware: Hackers Stole Significant Customer Data

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Craneware disclosed in a London Stock Exchange filing that hackers stole a "significant volume" of customer data — including a "percentage" of employee data, customer data, and partner records — though the company says the intruders appear to have been expelled from its systems.
- The company's flagship billing and accounting software is used by thousands of clinics, hospitals, and pharmacies across the United States, and its 2021 acquisition of pharmacy software maker Sentry brought access to 147 million patient records collected over two decades.
- CEO Keith Neilson did not respond to questions about ransom demands, and CGO Ian Armstrong confirmed only that the investigation was ongoing; the source also notes it's unclear whether Craneware's email systems are functional during the attack.
- The breach follows TriZetto's March confirmation that hackers stole personal and health data for more than 3.4 million people during an earlier attack, and CareCloud's same-month disclosure of an electronic health records breach.
- Episource notified at least 5.4 million people last July that their information had been stolen, underscoring the source's explicit framing that hackers are increasingly targeting tech vendors that supply software to the US healthcare sector.
- The 2024 ransomware attack on UnitedHealth-owned Change Healthcare — attributed to a Russian-speaking gang — exposed records of at least 192 million people and remains the largest US healthcare data breach on record.
Why it matters: A breach at Craneware is a healthcare supply-chain hit: its billing platform touches thousands of US providers and its Sentry acquisition brought 147 million patient records, so a 'significant volume' exfiltration — even without confirmed data-type specifics — puts enormous medical and billing information at risk of extortion or public release. Craneware joins a 12-month run of healthcare-vendor breaches including TriZetto (3.4M), CareCloud, and Episource (5.4M), reinforcing the pattern of attackers compromising shared software suppliers to reach many providers at once.



