Shares in Craneware, an AIM-listed healthcare firm, fell sharply in early trading on Monday after the company announced it had been subjected to a cyberattack. The incident involved "unauthorised access to a subset of its data environment," with initial findings indicating that "a significant volume of file names were viewed and exfiltrated." The accessed data includes employee information as well as records belonging to a subset of customers and partners. Craneware has informed both the US Federal Bureau of Investigation (FBI) and the UK’s Information Commissioner’s Office (ICO) about the breach. The company is currently working with advisers to determine the exact nature and scope of the compromised data and to identify affected parties for notification. In response to the news, Craneware's stock price dropped by as much as 8.4% during the opening minutes of trading. The company's shares have seen a significant decline, falling by over 40% since the beginning of the year. Analysts at Panmure Liberum commented that regulators have previously penalized the delayed disclosure of breaches as severely as the breaches themselves, emphasizing the importance of consistent communication in future updates.