Craneware Cyberattack Exposes Employee and Customer Data

Craneware Cyberattack Exposes Employee and Customer Data

First seen 20 Jul 2026, 09:01 UTC EdinburghliveUk.Finance.YahooThecyberexpressSharepricesKalkine+15 89% similarity 57.6

Article Content

Browse articles
ThreatCluster

Craneware plc, a healthcare software provider, reported a cyberattack on July 20, 2026, involving unauthorized access to its data environment. Investigations revealed that a significant volume of file names was viewed and exfiltrated, including employee data and some customer and partner records. The company stated that much of the accessed data is non-sensitive or already public regulatory information. Despite the breach, customer services and operations remained unaffected. Craneware activated its incident response plan and engaged external cybersecurity specialists to assist with the investigation. The company has notified relevant authorities, including the UK's Information Commissioner's Office and the US Federal Bureau of Investigation. Ongoing assessments aim to determine the full scope of the data involved and identify affected parties.

Key Points: • Craneware confirmed unauthorized access to its data environment on July 20, 2026. • A significant volume of file names, employee data, and some customer records were exfiltrated. • The incident has been contained, with no disruption to customer services reported.

ThreatCluster AI

Timeline

2026-07-20
Craneware reports cyberattack
Craneware disclosed unauthorized access to its data environment, revealing that a significant volume of file names was viewed and exfiltrated.
Kalkine
2026-07-20
Incident response activated
Craneware's Board activated its incident response plan and appointed external cybersecurity specialists to investigate the breach.
Heraldscotland
2026-07-20
Data assessment ongoing
Craneware is assessing the nature and scope of the compromised data, which includes employee and customer records.
Thecyberexpress
2026-07-20
Regulatory notifications made
Craneware notified the UK's ICO and the US FBI about the cyber incident as part of its compliance obligations.
Insurancebusinessmag

Community

Browse all →