Health tech firm Craneware admits “significant volume” of customer and employee data exposed in cyber attack
The incident has been contained and Craneware has launched a probe into the breach
Scottish health tech company Craneware has revealed customer and employee data has been exposed in a “security incident”.
In a notice filed with the London Stock Exchange (LSEG) on 20 July, the company said it had launched an investigation into the attack, which has now been contained.
“The company's incident response plan has been activated, including the appointment by the Board of external cybersecurity and forensic specialists,” the advisory reads.
“Their investigation is ongoing, alongside the Craneware IT team and the Company's retained cyber security service providers. There has been no disruption to customer services or to the company’s operations.”
A preliminary investigation into the breach found that a “significant volume” of file names was viewed and exfiltrated by unauthorized individuals, although the company noted these weren’t sensitive and were already publicly available.
“A percentage of employee data as well as a subset of customer and partner records have been accessed and exfiltrated,” Craneware added.
Craneware has since notified relevant regulators and law enforcement agencies, including the UK Information Commissioner’s Office (ICO) and the FBI.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
The Edinburgh-headquartered company provides accounting and billing software for US healthcare operators, partnering with around 2,000 hospitals across the country.
This makes it a prime target for cyber criminals, according to Trevor Dearing, director of critical infrastructure at Illumio.
“Healthcare technology providers have become prime targets because they offer cybercriminals a shortcut into the healthcare supply chain,” he said. “Why target one hospital when you can target a provider connected to thousands?”
Attacks on the UK healthcare system and associated vendors have increased significantly over the last year, according to a recent study from SonicWall. Figures published by the cybersecurity firm in June highlighted a tenfold increase in attacks so far in 2026.
Data collected through SonicWall's Intrusion Prevention System (IPS) showed upwards of 260,000 attempted cyber attacks between January and May this year.
While the Craneware incident has been contained, Dearing noted that employees and customers should still remain vigilant for potential follow-up attacks such as phishing - a common tactic employed in the wake of breaches.
“Even where stolen information appears low risk, employee, customer and partner data can be used to fuel phishing, social engineering and follow-on attacks,” he said.
“Employees, customers, and partners should remain cautious of any unsolicited communication or suspicious activity on their networks.”
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.
He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.
For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.
-
Cohesity taps Seb Fitzjohn to lead European partner strategyNews The former ServiceNow executive will oversee the vendor’s channel go-to-market efforts across the region
-
UK tech trade associations hit out amidst reports DSIT could be scrappedNews The move could see the DSIT incorporated within a larger business department
-
US healthcare firm postponed procedures after cyber attack knocked systems offlineNews The incident at Kettering Health disrupted procedures for patients
-
US healthcare data breaches are out of control – over 400 million patient records have been exposed in the last two yearsNews There's been a huge surge in the number of healthcare data breaches in recent years
-
More than 5 million Americans just had their personal information exposed in the Yale New Haven Health data breach – and lawsuits are already rolling inNews A data breach at Yale New Haven Health has exposed data belonging to millions of people – and lawsuits have already been filed.
-
Healthcare organizations are turning a blind eye to phishing attacksNews A survey reveals that most attacks go unreported, putting patient data at risk
-
Healthcare systems are rife with exploits — and ransomware gangs have noticedNews Nearly nine-in-ten healthcare organizations have medical devices that are vulnerable to exploits, and ransomware groups are taking notice.
-
More than 300,000 US healthcare patients impacted in suspected Rhysida cyber attacksNews Two US healthcare organizations have warned threat actors were able to breach their internal systems, exposing more than 300,000 individuals.
-
‘It’s your worst nightmare’: A batch of €5 hard drives found at a flea market held 15GB of Dutch medical records – and experts warn it could’ve caused a disastrous data breachNews Robert Polet made a startling discovery after finding hard drives on sale for €5 each in a flea market.