Craneware Confirms Data Theft After Cybersecurity Incident
Healthcare financial software provider Craneware has confirmed that attackers accessed part of its data environment and removed information. The compromised material included file names, employee data, and records connected to some customers and partners.
Craneware disclosed the incident on July 20, 2026, through a regulatory announcement. Its initial investigation found that attackers viewed and exfiltrated a significant volume of file names, although much of the associated information may be non-sensitive or already public.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
The company has contained the incident and reported no disruption to customer services or business operations. Craneware has not disclosed how the attackers gained access, when the intrusion began, or how many organizations and individuals it may affect.
What data did attackers steal from Craneware?
According to Craneware’s cybersecurity incident notice, investigators established that attackers viewed and exfiltrated a significant volume of file names.
The company also confirmed the theft of a percentage of Craneware employee data. A subset of customer and partner records was accessed and removed from the affected environment.
Craneware has not identified the exact types of employee, customer, or partner information involved. It also has not confirmed the theft of patient records, protected health information, financial details, passwords, Social Security numbers, or medical information.
| Incident detail | Current status |
|---|---|
| File names | A significant volume was viewed and exfiltrated |
| Employee data | An unspecified percentage was accessed and exfiltrated |
| Customer records | An unspecified subset was accessed and exfiltrated |
| Partner records | An unspecified subset was accessed and exfiltrated |
| Patient or protected health information | Not confirmed |
| Number of affected people | Not disclosed |
Craneware says the cyberattack has been contained
Craneware activated its incident response plan after identifying unauthorized access to a subset of its data environment. Its board appointed external cybersecurity and digital forensic specialists to investigate the compromise.
Those specialists are working with Craneware’s internal IT team and its existing cybersecurity service providers. External investigators reported finding no residual indicators of compromise linked to the incident in the company’s systems.
The absence of identified indicators supports Craneware’s statement that it has contained the incident. However, the investigation remains open while specialists determine the precise nature, sensitivity, and scope of the stolen information.
- Customer-facing services remain operational.
- Craneware reported no disruption to its wider operations.
- External cybersecurity and forensic specialists are investigating.
- No residual indicators linked to the incident were found in company systems.
- The assessment of the stolen records remains in progress.
What is still unknown about the Craneware breach?
Craneware has released only preliminary findings. The company has not named a suspected attacker or connected the incident to any known ransomware, extortion, or data-theft group.
It has not disclosed the initial access method, the length of unauthorized access, or whether stolen credentials, software vulnerabilities, phishing, or another technique enabled the intrusion.
The company also has not said whether attackers encrypted systems or demanded payment. The lack of operational disruption does not establish whether the incident involved an attempted ransomware attack or data-focused extortion.
| Unanswered question | Information disclosed |
|---|---|
| Who conducted the attack? | No attacker identified |
| How did attackers enter? | Initial access method not disclosed |
| How long did access continue? | No timeline provided |
| Was ransomware deployed? | Not confirmed |
| Was a ransom demanded? | Not disclosed |
| How many people are affected? | Still under assessment |
ICO and FBI notified about the incident
Craneware has notified relevant regulators and law enforcement agencies. These include the UK Information Commissioner’s Office and the United States Federal Bureau of Investigation.
The company is working with advisers to identify affected parties and prepare appropriate notifications. It may issue additional regulatory notices as investigators learn more about the compromised records.
In its regulatory disclosure, Craneware said it would update the market when appropriate. The company had not provided an estimated completion date for the investigation at the time of publication.
Why the Craneware incident matters to healthcare organizations
Craneware supplies financial performance and revenue integrity technology to hospitals and health systems. Its products support healthcare pricing, revenue, cost management, pharmacy programs, compliance, and operational analysis.
The company describes Trisus as a cloud-native healthcare financial intelligence platform. It combines revenue, margin, operational, and other enterprise data to help healthcare organizations manage financial performance.
This position makes the scope of the incident important to Craneware customers. However, the company has not said that attackers accessed production hospital environments or interrupted services delivered through Trisus.
Craneware’s financial intelligence platform runs on Microsoft Azure, according to the company. Craneware has not attributed the breach to Azure or identified the specific systems affected by the unauthorized access.
What employees, customers, and partners should do
Potentially affected people should wait for direct notifications from Craneware before assuming that their information was stolen. The company is still identifying affected parties and determining which records require formal disclosure.
Employees and business contacts should remain cautious about unexpected messages that reference Craneware, its investigation, invoices, account access, security reviews, or updated payment instructions. Stolen business records can help criminals make fraudulent messages appear credible.
The US Cybersecurity and Infrastructure Security Agency advises users to avoid clicking suspicious links or attachments. Its phishing guidance also recommends reporting suspicious messages instead of responding to them.
- Check official Craneware communications for an individual notification.
- Verify unexpected requests through a known telephone number or contact method.
- Do not submit passwords through links in unsolicited emails.
- Confirm changes to payment details through a separate communication channel.
- Enable multifactor authentication on work and personal accounts where available.
- Report suspicious messages to the relevant employer or security team.
Recipients should treat urgent requests involving passwords, invoices, bank details, or account verification with caution. The CISA recommendations say users should resist pressure to act immediately and avoid opening questionable links or attachments.
Craneware has contained the known intrusion, but important questions about the stolen data remain unanswered. The full impact will depend on what investigators find and which employees, customers, and partners receive breach notifications.
FAQ
Attackers gained unauthorized access to part of Craneware’s data environment. They viewed and exfiltrated file names, employee data, and a subset of customer and partner records.
Craneware confirmed the theft of a significant volume of file names, an unspecified percentage of employee data, and a subset of customer and partner records. It has not identified the exact information in those records.
Craneware has not confirmed that patient records or protected health information were accessed. Its investigation into the nature and sensitivity of the stolen data remains ongoing.
No disruption to customer services or company operations was reported. Craneware says it contained the incident.
Craneware has not identified the threat actor. No ransomware or data-extortion group had publicly claimed responsibility at the time of publication.
Craneware notified the UK Information Commissioner’s Office, the US Federal Bureau of Investigation, and other relevant regulators and law enforcement agencies.
They should monitor official communications, verify unexpected requests through trusted contact methods, enable multifactor authentication, and avoid suspicious links or attachments.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages