Scottish healthcare technology firm Craneware has disclosed a cybersecurity incident resulting in unauthorized access to a portion of its data environment. The company, known for providing financial performance and operational analytics solutions to the U.S. healthcare sector, identified that a significant volume of file names were viewed and exfiltrated by threat actors. Additionally, some employee data, as well as a subset of customer and partner records, were accessed and removed.
Upon detecting the breach, Craneware activated its incident response plan, enlisting external cybersecurity and forensic specialists to assist its internal IT team in the investigation. The company has assured stakeholders that the incident has been contained, with no disruption to customer services or internal operations. External investigators have confirmed the absence of residual indicators of compromise within Craneware’s systems, suggesting that the attackers no longer have access.
While the company believes that much of the compromised data is non-sensitive or already publicly available regulatory information, the exposure of employee, customer, and partner records raises concerns. The exact nature and sensitivity of the exfiltrated data are still under assessment. Craneware has notified relevant authorities, including the UK’s Information Commissioner’s Office (ICO) and the U.S. Federal Bureau of Investigation (FBI), indicating potential implications for data subjects in both countries.
Given Craneware’s extensive partnerships with over 2,000 U.S. hospitals and nearly 10,000 clinics and pharmacies, the breach underscores the vulnerabilities within the healthcare supply chain. Experts caution that even seemingly low-risk data can be exploited for phishing and other follow-up attacks. A recent report highlighted a tenfold increase in UK healthcare-related cyberattacks in early 2026, emphasizing the escalating threat landscape.
In response to the breach, Craneware is working with advisors to identify affected parties and prepare appropriate notifications in accordance with regulatory obligations. The company has not disclosed specific details regarding the number of individuals impacted, the attack vector, or whether any ransomware or extortion group has claimed responsibility.
This incident serves as a stark reminder of the critical importance of robust cybersecurity measures within the healthcare sector. Organizations connected to Craneware should remain vigilant, review communications from the company, and monitor for potential phishing attempts or other malicious activities stemming from the exposed data.