Health-tech firm Craneware says customer, employee and partner data stolen in cyberattack
Edinburgh-based healthcare billing software maker Craneware disclosed that attackers gained unauthorised access to part of its data environment and exfiltrated a significant volume of employee, customer and partner records before being expelled.
- Victim
- Craneware
On 20 July 2026, Craneware β the Edinburgh-based healthcare financial-performance software company whose products are used by US hospitals and health systems to manage revenue integrity, billing compliance and pharmacy operations β disclosed that it had suffered a cyberattack in which intruders gained unauthorised access to part of its data environment and stole data. In a statement to the London Stock Exchange, where the company is listed on the Alternative Investment Market (AIM), Craneware said a percentage of employee data and a subset of customer and partner records had been accessed and removed from its systems.
Craneware's flagship software, delivered through its Trisus cloud platform, is relied upon by thousands of hospitals, clinics and pharmacies across the United States. The company said investigators had established that a significant volume of file names was viewed and exfiltrated, though its current assessment was that a large element of the data involved was non-sensitive or already-public regulatory information. Craneware did not attribute the attack to any named threat actor.
A contained breach with an ongoing investigation
Craneware said the attackers appeared to have been expelled from its systems and that external forensic specialists appointed by the board had confirmed there were no residual indicators of compromise. The company reported no disruption to customer services or to its own operations, and said it had notified regulators and law enforcement β including the UK Information Commissioner's Office and the US Federal Bureau of Investigation. Its shares fell around 6% on the disclosure as investors weighed the reputational exposure of a supplier embedded in the billing workflows of a large share of US healthcare providers.
Open questions
At the time of disclosure the investigation remained ongoing, and several details were unconfirmed. Craneware did not quantify exactly how many individuals or customer organisations were affected, did not fully characterise the categories of stolen data beyond its preliminary "largely non-sensitive" assessment, and did not name a threat actor or report any ransom demand. With the intrusion contained, the foothold eradicated and no operational impact reported, the incident's status was best described as contained β while the scope of the exfiltrated records was still being assessed.
Timeline
Craneware discloses via a statement to the London Stock Exchange (AIM) that attackers gained unauthorised access to part of its data environment and stole employee, customer and partner records; the company says the intrusion has been contained and the attackers expelled.
Craneware says a significant volume of file names was viewed and exfiltrated, with its current assessment that much of the data is non-sensitive or already-public regulatory information, and reports no disruption to customer services or operations. Shares fall around 6%.
Sources
- techcrunch.comhttps://techcrunch.com/2026/07/20/hackers-stole-significant-amount-of-data-from-tech-firm-relied-on-by-thousands-of-us-hospitals-and-pharmacies/
- itpro.comhttps://www.itpro.com/security/data-breaches/health-tech-firm-craneware-admits-significant-volume-of-customer-and-employee-data-exposed-in-cyber-attack
- computing.co.ukhttps://www.computing.co.uk/news/2026/security/cranewear-confirms-data-breach-after-cyberattack
- thecyberexpress.comhttps://thecyberexpress.com/craneware-data-breach/
- proactiveinvestors.comhttps://www.proactiveinvestors.com/companies/news/1095682/craneware-reveals-cyber-attack-with-employee-and-customer-data-stolen-1095682.html