2026 Craneware — cyber incident; employee + customer/partner data exfiltrated (Jul 20)
Data compromised
Employee data; subset of customer and partner records; file metadata (patient PHI status under assessment per The Record)
Technical writeup
Craneware plc (AIM: CRW.L), a UK-listed healthcare revenue-cycle software vendor serving more than 2,000 U.S. hospitals and ~10,000 clinics/pharmacies, disclosed on 20 July 2026 that it identified unauthorized access to a subset of its data environment. An RNS/LSE notice and The Record reporting said incident response was activated with external forensics; operations and customer hospital services were not disrupted and no residual compromise indicators remained. Craneware notified the UK ICO and US FBI. Investigations found a significant volume of file names were viewed and exfiltrated; much appears non-sensitive or public regulatory data, but a percentage of employee records and a subset of customer and partner records were taken. The company is still assessing whether patient information was involved and preparing notifications; no attested victim count published at disclosure.
Root cause
Unauthorized access and data exfiltration from subset of data environment
References
- https://www.investegate.co.uk/announcement/rns/craneware--crw/notice-of-cyber-security-incident/9675808
- https://www.londonstockexchange.com/news-article/CRW/notice-of-cyber-security-incident/17694735
- https://therecord.media/software-provider-for-us-hospitals-customer-data-breach
- https://thecyberexpress.com/craneware-data-breach/
- https://www.cybersecuritydive.com/news/craneware-health-care-data-breach/825643/
- https://uk.finance.yahoo.com/news/health-tech-firm-craneware-says-072649437.html
- https://www.computing.co.uk/news/2026/security/cranewear-confirms-data-breach-after-cyberattack