Craneware, a UK-based healthcare software provider serving over 2,000 US hospitals and pharmacies, announced that a data breach had occurred. This cyberattack resulted in the theft of employee, customer, and partner data, though the specifics of the stolen information are still under investigation.
Craneware provides vital billing and patient management software to healthcare providers. Despite the breach, Craneware confirmed that its operations and service delivery to hospitals and pharmacies were not disrupted.
The data breach has been reported to the FBI and the UK's Information Commissioner’s Office. Craneware is working with external forensic experts to ascertain the extent and impact of the breach. Hackers have been removed from the system, but investigations are ongoing.
Craneware's acquisition of pharmacy software maker Sentry in 2021 expanded its access to a massive database of 147 million patient records. While it's not confirmed if patient data was involved, the fact that Craneware manages sensitive information heightens the incident's potential impact.
Craneware continues to assess the breach's impact while ensuring the integrity of its services. The industry is closely monitoring the situation due to the sensitive nature of healthcare data involved.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Healthcare facilities operator Nutex disclosed that patient and employee data were stolen during a cyberattack in August, with the company now facing extortion demands from the attackers. This incident impacts a healthcare provider operating 27 facilities across 12 states and highlights ongoing data security challenges in the healthcare sector.
Nutex Health confirmed a data breach where personal and business information was stolen, with the Gentlemen ransomware group claiming responsibility and threatening to leak the data. This incident highlights ongoing cybersecurity risks for healthcare providers and the increasing threat of data exfiltration by ransomware groups.
The ShinyHunters hacking group claims responsibility for a cyberattack on McKesson, a major U.S. pharmaceutical distributor, resulting in the exfiltration of millions of patient and employee records from cloud-hosted environments. This incident highlights ongoing vulnerabilities in healthcare data security and the effectiveness of social engineering tactics used by hacking groups.
Healthcare giant McKesson Corporation confirmed that the ShinyHunters extortion group exfiltrated customer data from its systems, with a deadline of September 1 for ransom negotiations. The breach affects a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units, potentially compromising sensitive health and personal information.
McKesson, a major healthcare and pharmaceutical distributor, disclosed a cybersecurity incident involving unauthorized access to third-party applications and data exfiltration. The ShinyHunters extortion group claims responsibility, stating they stole 284 million patient data records through vishing attacks on employees. This incident impacts a critical healthcare infrastructure provider and potentially exposes a large volume of sensitive patient data.
Nutex Health, a healthcare management company, reported unauthorized access to its network, resulting in the exfiltration of files that may contain confidential or private information. The company is investigating the scope of the breach, which could involve patient, employee, and operational data, and acknowledged the possibility of stolen data being leaked.
Employee benefits platform Paylogix disclosed a cyberattack that occurred in November, resulting in the theft of financial and health data belonging to tens of thousands of individuals. The incident, suspected to be linked to the Akira ransomware group, has led to notifications to state regulators and the organization of class-action lawsuits.
Hospital operator Nutex Health disclosed a cyberattack where an unauthorized third party exfiltrated data from its servers, including potentially private or confidential information. The company is investigating the scope of the breach and has engaged cybersecurity specialists and law enforcement.
Canada's Hospital for Sick Children (SickKids) experienced a cybersecurity incident that exposed personal information of current and former employees, job applicants, and staff from related organizations. This incident, believed to be linked to a third-party software application, marks the second cyberattack on the hospital since a 2022 ransomware event, highlighting ongoing vulnerabilities in healthcare sector cybersecurity.
The Hospital for Sick Children (SickKids) announced a cybersecurity incident that exposed personal information of current and former employees, as well as job applicants, due to a flaw in third-party software. This breach highlights the ongoing vulnerability of organizations to supply chain attacks and the sensitive nature of data collected through job application portals.
CareCloud, a health data company, confirmed that a March data breach exposed the personal and medical records of over 3.7 million patients. This incident is the fifth-largest health data theft reported in 2026 so far, highlighting ongoing vulnerabilities in healthcare data security.
The ransomware group "The Gentlemen" hijacked the Facebook page of AnMed, a nonprofit medical system, posting ransom demands and claims of exfiltrated data two weeks after an initial cyberattack. AnMed removed the unauthorized content and is investigating the incident, which has kept 10 facilities closed.
CareCloud, a U.S. health tech company, is notifying hundreds of thousands of individuals that their medical records were stolen in a cyberattack earlier this year. Hackers accessed one of its electronic health record data stores for six days in March, compromising sensitive personal and financial information for at least 345,000 people, with the number expected to rise.
Craneware, a UK-based healthcare software provider, reported a cyberattack resulting in the theft of a significant volume of customer data. The breach impacts numerous U.S. hospitals and pharmacies that rely on Craneware's services for billing and patient records management.
Craneware, a software provider for over 2,000 U.S. hospitals, revealed a data breach where hackers accessed employee and customer information. They reported the incident to the FBI and reported that while some compromised data was non-sensitive, the exact details remain unclear, raising concerns about patient data privacy.