Cyber Security News

Craneware Data Breach – Hackers Stole Significant Amount of Data

Healthcare financial software provider Craneware has confirmed a cybersecurity incident involving unauthorized access to a portion of its data environment.

The company reported that threat actors viewed and exfiltrated a substantial number of file names, along with some employee data, and a selection of customer and partner records.

On July 20, 2026, the London Stock Exchange’s Regulatory News Service published the incident disclosure from Craneware, which is listed on the AIM market under the ticker CRW.L.

The company provides healthcare financial performance, revenue intelligence, and operational analytics solutions through its Trisus cloud ecosystem.

Craneware Data Breach

According to Craneware, the attack has been contained, and there has been no disruption to customer-facing services or internal business operations. The company activated its incident response process immediately after detecting the compromise.

The board has appointed external cybersecurity and digital forensic specialists to assist with the investigation. Craneware’s internal IT team, along with retained security service providers, are also involved in the response effort.

External investigators have reportedly found no residual indicators of compromise within Craneware’s systems, indicating that the attackers are no longer active in the affected environment.

Craneware believes that much of the compromised data is non-sensitive or already publicly available regulatory information. However, the investigation revealed that some employee information, customer records, and partner records were accessed and removed from the environment.

The company has not disclosed the number of affected individuals, the threat actor, the attack vector, the duration of unauthorized access, the data involved, or whether any ransomware or extortion group has claimed responsibility.

Craneware is continuing to assess the nature, sensitivity, and scope of the stolen data. It is working with advisers to identify impacted parties and prepare notifications as required under applicable data protection and cybersecurity regulations.

The company has notified relevant authorities, including the UK Information Commissioner’s Office and the US Federal Bureau of Investigation.

These notifications suggest that the incident may impact data subjects or business operations across both the United Kingdom and the United States.

This breach is particularly significant because Craneware operates in the healthcare technology sector, where customer environments may contain financial, operational, billing, and regulatory information.

While Craneware has not confirmed whether protected health information or highly sensitive patient data was involved, affected customers should closely monitor future notifications.

Organizations connected to Craneware should review communications from the company, assess exposed account and contact information, and remain vigilant for targeted phishing attempts.

Attackers frequently use stolen employee and partner data to conduct convincing business email compromise schemes, credential theft, and subsequent social engineering campaigns. Craneware stated it will provide further updates as the investigation progresses.

The Privilege Paths Attackers See That You Don’t: BeyondTrust Pathfinder Platform Does It for You -> Get Free Identity Security Assessment

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago