Craneware plc—a UK-listed vendor whose software helps hospitals manage revenue and compliance—told investors on 20 July 2026 that attackers accessed and exfiltrated files from part of its data environment.
The company’s RNS notice is careful: operations kept running, customer services were not disrupted, and forensics found no lingering foothold. Still, a percentage of employee records and a subset of customer and partner records were taken alongside filenames that may include already-public regulatory material.
Why hospitals care
Craneware sits in the financial layer between providers and payers. Even metadata about which NHS or US hospital customers use which modules can help attackers craft credible vendor impersonation.
Action items
- Hospital finance teams: treat unexpected Craneware-themed MFA or invoice messages as suspicious until verified out-of-band.
- Employees: enroll in any monitoring Craneware offers once notifications go out.
Canonical record
https://breachhistory.com/craneware/craneware-cyberattack2026 — Investegate RNS.