Craneware plc confirmed on 20 July 2026 that it had detected a cybersecurity intrusion that allowed unauthorized access to part of its data environment and the exfiltration of a large number of file names. The healthcare financial performance software vendor said it activated its incident response plan, engaged external cybersecurity and forensic specialists, and that its customer services and operations have not been disrupted.
Scope of the incident
According to the company announcement, the attack targeted a segment of Craneware’s data estate. Initial analysis indicates that numerous file names were accessed and extracted. A substantial portion of those files appears to contain regulatory material that is non-sensitive or already public, but Craneware says employee data and a subset of client and partner records were also exposed.
Immediate response and external expertise
Management states it invoked its incident protocol and retained external cyber and forensic experts to lead the investigation alongside internal IT teams and its usual service providers. Those specialists have reported that, following their checks to date, there are no residual indicators of compromise in the company’s systems.
What data was affected?
Craneware reports that, in addition to largely non-sensitive regulatory documents, some files containing employee information and a limited number of client and partner records were viewed and exfiltrated. The company is currently assessing the precise nature and extent of the exposed items to distinguish sensitive information from public material—a critical step for notification obligations and remediation.
Regulatory notifications and implications
Craneware has notified the UK Information Commissioner’s Office (ICO) and the US Federal Bureau of Investigation (FBI), reflecting the geographic scope of potentially affected data and the applicability of multiple regulatory regimes. The company is working with advisors to identify impacted individuals and organizations and prepare legally required notifications.
Operational impact and message to customers
Craneware emphasizes that its services and operations have not been affected—an important point for a cloud provider serving healthcare finance functions, whose Trisus® platform is central to its offering. The lack of operational disruption and the absence of residual compromise indicators are intended to reassure customers about the integrity of the environments Craneware operates.
The investigation is ongoing, and the company has committed to issuing market updates as the review progresses. Clients, partners and employees have been asked to await formal communications for the definitive scope of affected data and any remediation measures Craneware proposes.

