Major US hospitals partner Craneware confirms data breach
The company works with thousands of American hospitals.

Image by Cybernews.
- Craneware said attackers stole a significant volume of data after unauthorized access to part of its systems.
- The Scotland-based healthtech firm serves more than 2,000 US hospitals and nearly 10,000 clinics and pharmacies.
- The company said some employee, customer, and partner records were taken, though most exposed data was reportedly non-sensitive.
- Craneware notified UK and US authorities, including the FBI, and said services and operations were not disrupted.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
UK healthtech company Craneware has been hit by a cyberattack, with attackers stealing a “significant volume” of data. British and American authorities, including the FBI, were informed about the attack.
Craneware reported that the company was responding to an attack on July 20th. According to a cybersecurity incident notice submitted to the London Stock Exchange, the company identified unauthorized access to a “subset of its data environment.”
Scotland-based Craneware provides accounting and billing software solutions to US healthcare providers. The company partners with over 2,000 US hospitals and supports nearly 10,000 clinics and retail pharmacies in the country.
According to the data breach notice, an ongoing investigation revealed that “a significant volume of file names were viewed and exfiltrated.” However, the company claims that most of the data is non-sensitive and is “already public regulatory data.”
“A percentage of Craneware employee data, as well as a subset of customer and partner records, have been accessed and exfiltrated,” the breach notice says.
While it’s unclear exactly which details were exposed in the Craneware data breach, attackers can exploit healthcare employee information. For one, attackers could target healthcare employees with tailor-made attacks.
The key reason here would be to gain lateral access through employees, then infiltrate healthcare organizations later. Hospitals, clinics, and pharmacies have troves of data that malicious actors covet. From personal details and medical records to insurance information, healthcare data is among the most valuable on the dark web.
A percentage of Craneware employee data, as well as a subset of customer and partner records, have been accessed and exfiltrated.Craneware said.
So far, the extent of the Craneware data breach remains unclear, as the company has not revealed the nature of the attack or how much data may have been exported. However, the company said that the “incident has been contained and there has been no disruption to customer services or to the company's operations.”
“The external specialists have confirmed that there are no residual indicators of compromise arising from the cybersecurity incident in the Company's systems,” Craneware said.
The healthtech firm, as required by law, notified relevant regulators and law enforcement agencies. In the UK, the Information Commissioner's Office (ICO) is responsible, while in the US, the FBI was notified of the data breach.
“The company is continuing to assess the precise nature and scope of all the data involved and is working with its advisers to identify affected parties and prepare appropriate notifications, including any required further notifications to relevant authorities, in each case in accordance with applicable regulatory obligations,” Craneware explained.
There is no shortage of attacks against companies and organizations in the healthcare sector. Recently, an American healthcare giant, Abbott Laboratories, reported it is investigating two cyber incidents: one involving its Cancer Diagnostics business and another affecting its LabCentral portal.
Meanwhile, last week, US health insurer Clover Health said threat actors gained access to employee accounts using social engineering techniques.
Check if your data has been leaked