2026-07-20
BlogGrey Wing Security4 min readGRCWhy a Milk Company and a Billing Software Vendor Both Belong in Your Security Review
A ransomware attack stopped Coca-Cola's Fairlife dairy plants from making milk. Four days later, Craneware, a UK billing software vendor, disclosed that hackers had stolen a "significant volume" of employee, customer, and partner data from systems supporting thousands of U.S. hospitals, clinics, and pharmacies. Coca-Cola confirmed its incident on July 16. TechCrunch reported Craneware's incident on July 20.
Neither company is a startup. Neither story is only about the company that was attacked.
Two different ways attackers win
The Fairlife attack and the Craneware breach show two failure modes in the same supply chain.
Fairlife's ransomware attack hit operational systems directly. Production stopped. That is the scenario most people picture when they hear "ransomware": files encrypted, a ransom note, and a business that cannot ship product until the incident is resolved.
Craneware's breach did not stop a production line. It moved patient, partner, and employee data out of one vendor's systems and created downstream compliance problems for hospitals and pharmacies that did not cause the breach and cannot fully control the vendor's response. Craneware's 2021 acquisition of pharmacy software maker Sentry gave it access to 147 million patient records collected over two decades. Craneware has not said how much of that data was exposed.
Both incidents involve ransomware and data theft. Only one requires you to operate a factory.
Craneware is the fourth healthcare-vendor breach this year
This is a pattern:
- TriZetto, March 2026: Confirmed hackers stole personal and health data belonging to 3.4 million people.
- CareCloud, March 2026: Reported a breach of a patient electronic health record store. The scope remains undisclosed.
- Episource, summer 2025: Began notifying at least 5.4 million people that their data had been stolen.
- Change Healthcare, 2024: Became the largest healthcare breach on record, exposing the medical and patient records of at least 192 million people.
Each company sold software or services to healthcare providers that never touched the attackers' keyboard. Those providers still had to notify patients, answer regulators, and explain the incident to their own customers.
You are Craneware to somebody
If your startup sells into healthcare, fintech, or another enterprise market, your company occupies a position in someone else's supply chain. A breach at your company becomes your customer's compliance incident, notification burden, and board question.
This is why enterprise buyers send security questionnaires before signing and why more buyers ask for a SOC 2 report. The questionnaire is the buyer's risk calculation before a breach, rather than after it.
Founders sometimes treat a questionnaire as a delay tactic or a box-checking exercise. Treat it as a list of evidence the buyer needs before accepting responsibility for a vendor relationship.
What this means for a 20 to 100 person company
You do not need a Craneware-sized breach to feel this risk. It appears in several concrete places.
In the sales process. A deal stalls while the prospect's security team asks for evidence: MFA enforcement, access logging, a named incident response process, and a data flow diagram.
In your vendor list. Payroll, support, billing, and other vendors may hold your customer or employee data. If one of them is breached, you inherit the notification and customer conversation even though you did not cause the incident.
In how quickly you close the gap. The missing items are usually a short, specific list: enforced MFA, a documented offboarding process, encrypted backups, and a written incident response plan. Many of these controls can be addressed in two to three weeks. SOC 2, once the basics are in place, usually takes months.
What to do next
Start with two lists:
- Pull your current vendor list and mark which vendors hold customer or employee data. Those vendors define your exposure when a supplier breach becomes your incident.
- Pull the last security questionnaire that stalled a deal and list the missing evidence. The result is usually a short, specific work list.
Grey Wing Security helps teams build the evidence, assign the owners, and track the security work that comes out of these reviews.