{"id":55150,"title":"Craneware Confirms Cyber Security Breach and Data Theft","publisher":"Stockmark.IT","author":"Stockmark.IT Website","published":"2026-07-20T09:28:31+00:00","modified":"2026-07-20T09:28:31+00:00","canonical_url":"https://stockmark.it/craneware-confirms-cyber-security-breach-and-data-theft/","markdown_url":"https://stockmark.it/craneware-confirms-cyber-security-breach-and-data-theft.md","json_url":"https://stockmark.it/craneware-confirms-cyber-security-breach-and-data-theft.json","category":"Health","categories":["Health","Health Tech","Med Tech","Medical technology"],"featured_image":"https://stockmark.it/wp-content/uploads/2026/07/craneware-confirms-cyber-security-breach-and-data-theft.avif","format":"news","language":"en-GB","content":"Shares in Craneware PLC declined 6% to 1,138 pence following the company’s disclosure of a cyber security incident that resulted in the unauthorised access and theft of employee, customer and partner data. The Edinburgh-based provider of healthcare financial performance software confirmed that hackers had penetrated a portion of its data environment.\n\nAccording to the company’s initial assessment, a substantial volume of file names were both viewed and extracted during the breach. Management has indicated that a significant proportion of the compromised data comprises non-sensitive information or material already available through public regulatory filings. However, the incident did involve the unauthorised access and removal of certain employee data alongside a subset of customer and partner records.\n\nThe company has stated that the security breach has been contained and that customer services and operational activities have continued without disruption. External forensic specialists engaged by the board have completed their preliminary investigation and confirmed the absence of any residual indicators of compromise within the company’s systems.\n\nCraneware has formally notified relevant regulatory authorities and law enforcement agencies in both jurisdictions where it maintains operations. The Information Commissioner’s Office in the United Kingdom and the Federal Bureau of Investigation in the United States have been informed of the incident, reflecting the company’s substantial commercial presence in the American healthcare market.\n\nThe software provider serves a client base of US hospitals and health systems, delivering solutions for revenue integrity, billing compliance and pharmacy operations through its Trisus cloud platform. The sensitivity of healthcare data makes the security of these systems a critical concern for customers operating under stringent regulatory frameworks.\n\nManagement continues to evaluate the precise nature and full scope of the data involved in the breach. The company is working with specialist advisers to identify all affected parties and prepare appropriate notifications, including any additional disclosures that may be required by regulatory bodies. Craneware’s incident response protocols were activated immediately upon discovery of the breach, with the internal IT team collaborating with retained cyber security providers and the newly appointed external forensic specialists.\n\nBroker Peel Hunt characterised such incidents as relatively commonplace within the sector and stated that the attack should not be viewed as an existential threat to the business. The firm maintained its buy recommendation and 1,700 pence price target on the shares.\n\nIn its research note, Peel Hunt highlighted that the incident did not involve the encryption of production systems, which would typically indicate a ransomware attack. The breach resulted in no service downtime or service level agreement credits for customers, and investigators found no evidence of ongoing attacker presence within the systems. Management has also indicated that the data mix was skewed away from protected health information, suggesting that the most severe data breach scenarios, comparable to the 2015 Anthem incident that compromised nearly 80 million individuals’ personal data, are unlikely to apply in this case.\n\nThe company has committed to providing further updates to the market as the investigation progresses and additional information becomes available."}