London-listed healthcare services firm hit by cyberattack
Shares in Craneware tumbled in early trading on Monday as the healthcare services firm revealed it had been hit by a cyberattack.
The AIM-listed business said the incident involved “unauthorised access to a subset of its data environment”. Early investigations suggest “a significant volume of file names were viewed and exfiltrated”.
Employee data as well as a subset of customer and partner records have been accessed, Craneware said, adding that it had notified the US FBI and the UK’s Information Commissioner’s Office of the incident.
Edinburgh-based Craneware, which provides cost management software for hospitals and healthcare systems, insisted that no customer services had been disrupted by the incident, adding that the data compromised in the attack was believed to be “non-sensitive.”
“The company is continuing to assess the precise nature and scope of all the data involved and is working with its advisers to identify affected parties and prepare appropriate notifications,” the firm said.
Craneware shares sunk as much as 8.9 per cent to 1,106p in the opening minutes of trading on Monday. The stock is down by more than 40 per cent since the start of the year.
All eyes on regulatory response
The scale of the regulatory response is likely to be key to assess the fallout from the incident, analysts said. Last year, Capita was fined £14m for a cyber breach which saw customer data stolen. The fine was reduced from £45m after Capita argued it had taken steps to boost its cyber resilience.
“Regulators [have previously] punished the later downplaying of the breach as much as the breach itself, so consistency between today’s reassuring wording and the next update is what matters,” analysts at Panmure Liberum said.
“The swing factor for severity in both dimensions is whether sensitive US patient data ends up in scope.”
Peel Hunt moved its buy recommendation and target price to “under review” pending further information.