Craneware shares slide after cyberattack

Craneware shares fell as much as 8.9% after the AIM-listed healthcare software company disclosed a cyberattack that resulted in employee data and a subset of customer and partner records being accessed and exfiltrated.

Craneware said a "significant volume" of file names had been viewed and stolen, but its current assessment is that much of the affected information was either non-sensitive or already publicly available regulatory data.

The Edinburgh-based company, which reported revenues of around £150m for FY25, said the incident had been contained, with no disruption to customer services or operations, although investigations into the full scope of the breach are continuing.

Its business is focused primarily on the US healthcare market, with a customer base that spans some 12,000 US hospitals, clinics and affiliated retail pharmacies.

It said the UK's Information Commissioner's Office and the FBI have been notified of the incident, while external cyber security and forensic specialists had confirmed there were no remaining indicators of compromise in its systems.

Craneware added it was "continuing to assess the precise nature and scope of all the data involved" and would notify affected parties where required.

The breach comes as businesses face an intensifying wave of cyberattacks. Marks & Spencer (M&S) suffered a major attack last year that disrupted online operations and cost the retailer more than £131m, while Jaguar Land Rover was forced to halt production for weeks following a cyberattack that rippled through its supply chain.

The incidents have heightened investor and regulatory scrutiny of cyber resilience, particularly in sectors handling large volumes of customer and operational data, including retail, manufacturing and healthcare.



Share Story:

Recent Stories