Craneware Confirms Data Theft After Cybersecurity Incident


Healthcare financial software provider Craneware has confirmed that attackers accessed part of its data environment and removed information. The compromised material included file names, employee data, and records connected to some customers and partners.

Craneware disclosed the incident on July 20, 2026, through a regulatory announcement. Its initial investigation found that attackers viewed and exfiltrated a significant volume of file names, although much of the associated information may be non-sensitive or already public.

The company has contained the incident and reported no disruption to customer services or business operations. Craneware has not disclosed how the attackers gained access, when the intrusion began, or how many organizations and individuals it may affect.

What data did attackers steal from Craneware?

According to Craneware’s cybersecurity incident notice, investigators established that attackers viewed and exfiltrated a significant volume of file names.

The company also confirmed the theft of a percentage of Craneware employee data. A subset of customer and partner records was accessed and removed from the affected environment.

Craneware has not identified the exact types of employee, customer, or partner information involved. It also has not confirmed the theft of patient records, protected health information, financial details, passwords, Social Security numbers, or medical information.

Incident detailCurrent status
File namesA significant volume was viewed and exfiltrated
Employee dataAn unspecified percentage was accessed and exfiltrated
Customer recordsAn unspecified subset was accessed and exfiltrated
Partner recordsAn unspecified subset was accessed and exfiltrated
Patient or protected health informationNot confirmed
Number of affected peopleNot disclosed

Craneware says the cyberattack has been contained

Craneware activated its incident response plan after identifying unauthorized access to a subset of its data environment. Its board appointed external cybersecurity and digital forensic specialists to investigate the compromise.

Those specialists are working with Craneware’s internal IT team and its existing cybersecurity service providers. External investigators reported finding no residual indicators of compromise linked to the incident in the company’s systems.

The absence of identified indicators supports Craneware’s statement that it has contained the incident. However, the investigation remains open while specialists determine the precise nature, sensitivity, and scope of the stolen information.

  • Customer-facing services remain operational.
  • Craneware reported no disruption to its wider operations.
  • External cybersecurity and forensic specialists are investigating.
  • No residual indicators linked to the incident were found in company systems.
  • The assessment of the stolen records remains in progress.

What is still unknown about the Craneware breach?

Craneware has released only preliminary findings. The company has not named a suspected attacker or connected the incident to any known ransomware, extortion, or data-theft group.

It has not disclosed the initial access method, the length of unauthorized access, or whether stolen credentials, software vulnerabilities, phishing, or another technique enabled the intrusion.

The company also has not said whether attackers encrypted systems or demanded payment. The lack of operational disruption does not establish whether the incident involved an attempted ransomware attack or data-focused extortion.

Unanswered questionInformation disclosed
Who conducted the attack?No attacker identified
How did attackers enter?Initial access method not disclosed
How long did access continue?No timeline provided
Was ransomware deployed?Not confirmed
Was a ransom demanded?Not disclosed
How many people are affected?Still under assessment

ICO and FBI notified about the incident

Craneware has notified relevant regulators and law enforcement agencies. These include the UK Information Commissioner’s Office and the United States Federal Bureau of Investigation.

The company is working with advisers to identify affected parties and prepare appropriate notifications. It may issue additional regulatory notices as investigators learn more about the compromised records.

In its regulatory disclosure, Craneware said it would update the market when appropriate. The company had not provided an estimated completion date for the investigation at the time of publication.

Why the Craneware incident matters to healthcare organizations

Craneware supplies financial performance and revenue integrity technology to hospitals and health systems. Its products support healthcare pricing, revenue, cost management, pharmacy programs, compliance, and operational analysis.

The company describes Trisus as a cloud-native healthcare financial intelligence platform. It combines revenue, margin, operational, and other enterprise data to help healthcare organizations manage financial performance.

This position makes the scope of the incident important to Craneware customers. However, the company has not said that attackers accessed production hospital environments or interrupted services delivered through Trisus.

Craneware’s financial intelligence platform runs on Microsoft Azure, according to the company. Craneware has not attributed the breach to Azure or identified the specific systems affected by the unauthorized access.

What employees, customers, and partners should do

Potentially affected people should wait for direct notifications from Craneware before assuming that their information was stolen. The company is still identifying affected parties and determining which records require formal disclosure.

Employees and business contacts should remain cautious about unexpected messages that reference Craneware, its investigation, invoices, account access, security reviews, or updated payment instructions. Stolen business records can help criminals make fraudulent messages appear credible.

The US Cybersecurity and Infrastructure Security Agency advises users to avoid clicking suspicious links or attachments. Its phishing guidance also recommends reporting suspicious messages instead of responding to them.

  1. Check official Craneware communications for an individual notification.
  2. Verify unexpected requests through a known telephone number or contact method.
  3. Do not submit passwords through links in unsolicited emails.
  4. Confirm changes to payment details through a separate communication channel.
  5. Enable multifactor authentication on work and personal accounts where available.
  6. Report suspicious messages to the relevant employer or security team.

Recipients should treat urgent requests involving passwords, invoices, bank details, or account verification with caution. The CISA recommendations say users should resist pressure to act immediately and avoid opening questionable links or attachments.

Craneware has contained the known intrusion, but important questions about the stolen data remain unanswered. The full impact will depend on what investigators find and which employees, customers, and partners receive breach notifications.

FAQ

What happened in the Craneware data breach?

Attackers gained unauthorized access to part of Craneware’s data environment. They viewed and exfiltrated file names, employee data, and a subset of customer and partner records.

What information did attackers steal from Craneware?

Craneware confirmed the theft of a significant volume of file names, an unspecified percentage of employee data, and a subset of customer and partner records. It has not identified the exact information in those records.

Did the Craneware breach expose patient data?

Craneware has not confirmed that patient records or protected health information were accessed. Its investigation into the nature and sensitivity of the stolen data remains ongoing.

Did the cyberattack disrupt Craneware services?

No disruption to customer services or company operations was reported. Craneware says it contained the incident.

Who carried out the Craneware cyberattack?

Craneware has not identified the threat actor. No ransomware or data-extortion group had publicly claimed responsibility at the time of publication.

Which authorities has Craneware notified?

Craneware notified the UK Information Commissioner’s Office, the US Federal Bureau of Investigation, and other relevant regulators and law enforcement agencies.

What should Craneware customers and employees do?

They should monitor official communications, verify unexpected requests through trusted contact methods, enable multifactor authentication, and avoid suspicious links or attachments.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages