← Craneware

2026 Craneware — cyber incident; employee + customer/partner data exfiltrated (Jul 20)

2026 Unknown records affected Share on X

Data compromised

Employee data; subset of customer and partner records; file metadata (patient PHI status under assessment per The Record)

Technical writeup

Craneware plc (AIM: CRW.L), a UK-listed healthcare revenue-cycle software vendor serving more than 2,000 U.S. hospitals and ~10,000 clinics/pharmacies, disclosed on 20 July 2026 that it identified unauthorized access to a subset of its data environment. An RNS/LSE notice and The Record reporting said incident response was activated with external forensics; operations and customer hospital services were not disrupted and no residual compromise indicators remained. Craneware notified the UK ICO and US FBI. Investigations found a significant volume of file names were viewed and exfiltrated; much appears non-sensitive or public regulatory data, but a percentage of employee records and a subset of customer and partner records were taken. The company is still assessing whether patient information was involved and preparing notifications; no attested victim count published at disclosure.

Root cause

Unauthorized access and data exfiltration from subset of data environment

References