Breaches · 55 days ago
Craneware’s real problem is not outage. It is that a healthcare supplier can be breached, stay online, and still leak the records that tie hospitals, customers, and employees together. Standard availability-focused incident response would miss that downstream exposure.
The company says attackers got into a subset of its internal environment, copied a large number of file names, and took some employee data plus customer and partner records. Craneware says its services to more than 2,000 US hospitals were not disrupted, and it has contained the intrusion and brought in outside investigators.
That leaves the threat in the data, not the uptime. Even if the platform stays live, stolen vendor records can feed follow-on targeting of hospitals, partners, and staff across the healthcare supply chain.
4 sources covering this story
US Hospital Finance Software Provider Craneware Reports Data Theft
Craneware, a provider of financial software for US healthcare organizations, has disclosed a cyber incident involving unauthorized access and data theft
Edinburgh-based tech firm Craneware said customer data was stolen during a cyberattack.
The Record from Recorded Future
Software provider to more than 2,000 US hospitals says hackers stole employee and customer data
Craneware, which is headquartered in Edinburgh and listed on London's AIM market, told investors it detected unauthorized access to a “subset” of its data environment and has since brought in outside forensic investigators.
Hackers steal customer data from major hospital software vendor
The breach is another reminder of how vulnerable the healthcare industry is to supply-chain attacks.
Part of the PlainSec briefing for 2026-07-22