Health tech firm Craneware admits “significant volume” of customer and employee data exposed in cyber attack

The incident has been contained and Craneware has launched a probe into the breach

Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.
(Image credit: Getty Images)

Scottish health tech company Craneware has revealed customer and employee data has been exposed in a “security incident”.

In a notice filed with the London Stock Exchange (LSEG) on 20 July, the company said it had launched an investigation into the attack, which has now been contained.

“The company's incident response plan has been activated, including the appointment by the Board of external cybersecurity and forensic specialists,” the advisory reads.

“Their investigation is ongoing, alongside the Craneware IT team and the Company's retained cyber security service providers. There has been no disruption to customer services or to the company’s operations.”

Latest Videos From

A preliminary investigation into the breach found that a “significant volume” of file names was viewed and exfiltrated by unauthorized individuals, although the company noted these weren’t sensitive and were already publicly available.

“A percentage of employee data as well as a subset of customer and partner records have been accessed and exfiltrated,” Craneware added.

Craneware has since notified relevant regulators and law enforcement agencies, including the UK Information Commissioner’s Office (ICO) and the FBI.

The Edinburgh-headquartered company provides accounting and billing software for US healthcare operators, partnering with around 2,000 hospitals across the country.

This makes it a prime target for cyber criminals, according to Trevor Dearing, director of critical infrastructure at Illumio.

“Healthcare technology providers have become prime targets because they offer cybercriminals a shortcut into the healthcare supply chain,” he said. “Why target one hospital when you can target a provider connected to thousands?”

Attacks on the UK healthcare system and associated vendors have increased significantly over the last year, according to a recent study from SonicWall. Figures published by the cybersecurity firm in June highlighted a tenfold increase in attacks so far in 2026.

Data collected through SonicWall's Intrusion Prevention System (IPS) showed upwards of 260,000 attempted cyber attacks between January and May this year.

While the Craneware incident has been contained, Dearing noted that employees and customers should still remain vigilant for potential follow-up attacks such as phishing - a common tactic employed in the wake of breaches.

“Even where stolen information appears low risk, employee, customer and partner data can be used to fuel phishing, social engineering and follow-on attacks,” he said.

“Employees, customers, and partners should remain cautious of any unsolicited communication or suspicious activity on their networks.”

FOLLOW US ON SOCIAL MEDIA

Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.

You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.

Ross Kelly
News and Analysis Editor

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.

He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.

For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.