
Medical Billing Meltdown: Hackers Raid Craneware Systems for Massive Data Haul
Hackers hit UK-based medical billing provider Craneware in a fresh cyberattack, stealing a huge volume of private files from its corporate network. Thousands of hospitals, clinics, and pharmacies across the United States rely on Craneware software to manage daily billing operations and track patient care costs.
In a regulatory statement filed with the London Stock Exchange, Craneware stated that it kicked the intruders off its network. Technical teams are still investigating the full scope of the intrusion to figure out what went wrong. The company admitted that cybercriminals exfiltrated a slice of employee files, customer information, and business partner records. Craneware has not confirmed whether patient medical histories were stolen during the raid.
Craneware plays a massive role behind the scenes of American healthcare. Its software processes patient billing records, handles insurance claims, and tracks prescription transactions every day. When Craneware bought pharmacy software provider Sentry back in 2021, it absorbed databases holding over 147 million patient records spanning two decades of medical care. That massive library of sensitive records makes Craneware a prime target for digital extortionists.
Craneware Chief Executive Officer Keith Neilson did not answer inquiries about whether the hackers made ransom demands or established direct contact with company executives. Chief Growth Officer Ian Armstrong confirmed the company continues to investigate the breach but declined to provide additional details about the incident. It remains unclear if internal email networks at Craneware are fully functional following the ongoing containment efforts.
This breach fits into a growing trend of cybercriminals striking software vendors that supply critical digital infrastructure to medical networks. Instead of attacking individual hospitals one by one, bad actors target central software vendors. By breaking into a single software provider like Craneware, attackers gain backdoor access to mountains of sensitive patient data. They then threaten to publish private records online to force executives into paying heavy ransom demands.
The attack on Craneware continues a relentless wave of healthcare breaches over the last year. In March, revenue technology vendor TriZetto revealed that hackers stole private data belonging to more than 3.4 million patients. That same month, cloud storage vendor CareCloud suffered a breach impacting its electronic health record databases. Last year, medical billing firm Episource notified at least 5.4 million individuals that intruders stole their personal information.
The largest healthcare cyberattack on record happened in 2024 when hackers struck Change Healthcare, a subsidiary of UnitedHealth Group. That attack exposed the medical files of at least 192 million people, compromising records for a massive portion of the American population.
Healthcare providers depend heavily on third-party software tools to keep billing systems moving. When a central vendor suffers a breach, hospitals face massive administrative delays, disrupted payment channels, and potential privacy liabilities. As these cyberattacks stack up, medical organizations face rising pressure to audit their software vendors and demand tighter digital security standards before another breach exposes millions more patients.







