Craneware Confirms Data Theft After Cyberattack

Craneware Confirms Data Theft After Cyberattack, Investigations Underway

Craneware Confirms Data Theft After Cyberattack, Investigations Underway

Hackers compromise healthcare vendor serving thousands of healthcare providers. Image: Generated with Google’s Nano Banana 2.

Healthcare software vendor Craneware confirmed attackers stole data during a cyberattack, underscoring growing cybersecurity risks facing healthcare suppliers.

Verfasst von
Joseph Ofonagoro
Joseph Ofonagoro
Jul 21, 2026

Hackers have stolen data from Craneware, a healthcare software provider serving thousands of U.S. hospitals and pharmacies, highlighting how cybercriminals continue to target vendors that sit at the center of the healthcare supply chain.

Craneware, a UK-based healthcare software vendor, said attackers gained unauthorized access to part of its network and exfiltrated a significant amount of information. The company has not disclosed how the breach occurred or identified those responsible.

According to the company’s filing with the London Stock Exchange, services remained operational, and the company has not confirmed that patient data was compromised. However, investigations from both US and UK agencies have commenced and are still determining the scope of the incident.

The breach is the latest in a series of cyberattacks targeting healthcare organizations and the vendors that support them.

Many of the incident’s details remain unknown

The company, in its Monday filings, notes that the attack has been contained, and it has so far determined that a “significant volume of file names were viewed and exfiltrated” by the threat actors.

The company also confirmed “that there are no residual indicators of compromise” left within its network.

However, the Monday announcement says nothing about the attack’s duration, method, initial access vector, or the attacker’s identity. The impact on affected customers, including the exact data accessed, the number of customers affected, and whether the attackers have reached out for ransom, has also not been revealed.

The company says it is still investigating and has contacted the Information Commissioner’s Office in the UK, and because a substantial part of its customer base is in the US, the FBI.

TechCrunch noted that Craneware acquired Florida-based pharmacy software developer Sentry in 2021. While Sentry maintains records relating to approximately 147 million patients, Craneware has not said whether any of that data was affected.

The company also partners with US organizations including Microsoft and the National Rural Health Association, per a report from Cybersecurity Dive.

Advertisement

Healthcare providers increasingly under attackers’ sights

While several outlets frame Craneware’s breach as potentially having a severe impact given its popularity in the healthcare industry, it is not an isolated incident. In fact, it appears to be part of an ongoing focus by threat actors on the healthcare industry.

More interestingly, a good portion of these breaches affect healthcare vendors rather than hospitals or clinics directly. The Change Healthcare breach of 2024 and the Xsolis breach are major examples of such.

The reasons for this aren’t far-fetched. Healthcare vendors not only sit on top of extremely valuable and sensitive data but also have little tolerance for the kinds of disruptions that cyberattacks bring. That is because any such disruptions can quickly move down to the several hospitals, clinics, or pharmacies reliant on them.

Must-read security coverage

A reminder for all

The Craneware breach is another reminder that cybersecurity doesn’t stop at an organization’s own network. Hospitals and healthcare providers increasingly rely on third-party vendors to handle billing, revenue cycle management, pharmacy operations, and other critical functions, meaning those vendors often hold large amounts of sensitive business and, in some cases, healthcare-related data.

For enterprises, the incident is a reason to reassess vendor risk. That includes understanding what information suppliers collect and store, how that data is protected, what security controls they have in place, and how quickly they can detect and disclose a breach.

Even organizations with a mature internal security posture can still face data exposure if a trusted software provider is compromised, highlighting the importance of vendor oversight in any cybersecurity strategy.

Advertisement

Every hospital, clinic, or pharmacy that relies on Craneware has its own customers. For these patients, the breach is a reminder that their personal information may be handled by companies beyond the healthcare provider they interact with.

While these patients often have little control over which third-party vendors are used, they should understand their rights to be notified if their data is exposed and pay close attention to any breach notices or guidance issued by their healthcare provider.

As healthcare organizations continue outsourcing critical software and operational services, vendor security is becoming just as important as protecting internal systems. Incidents like Craneware’s demonstrate how a breach at a single supplier can ripple across the broader healthcare ecosystem.

Other News: A dangerous Android malware campaign is using fake banking and government apps to hijack phones across Southeast Asia, giving scammers remote control over victims’ devices and access to sensitive financial data.

Joseph Ofonagoro

Joseph is a technical writer with about three years of experience creating clear, practical content across consumer technology, startups, tutorials, and cybersecurity. He is also advancing a career in cyber threat intelligence, driven by a strong interest in the responsible use of technology and its role in protecting people, organizations, and digital systems. His passion for cybersecurity grew out of a broader commitment to helping others understand technology safely and effectively. As an undergraduate at the National Open University of Nigeria, he leads a community of technology enthusiasts, guiding beginners, sharing learning resources, and helping students build confidence as they explore careers in tech. Joseph’s writing combines technical curiosity with an accessible, beginner-friendly style. In addition to his editorial work, he periodically shares cybersecurity case studies and research reports on social media, covering threat trends, security lessons, and practical insights for readers interested in cyber awareness and digital safety.