Hackers breached a major healthcare industry software supplier and stole a large trove of files, the company announced on Monday.
The British software firm Craneware, which makes software that helps companies track their financial performance and manage governance requirements, published a regulatory filing about “a cyber security incident involving unauthorised access to a subset of its data environment,” including the theft of “a significant volume” of files that included “employee data as well as a subset of customer and partner records.”
“The current assessment is that a large element of the data involved is non-sensitive or already public regulatory data,” Craneware said, although it added that an investigation by internal IT staff and third-party cybersecurity firms was ongoing.
Although Craneware is a British company, its website heavily markets its products to American healthcare firms, and it lists several U.S. trade associations and tech companies — including Microsoft and the National Rural Health Association — as strategic partners.
More than 2,000 healthcare organizations and nearly 10,000 clinics and retail pharmacies use Craneware’s product, according to its website, meaning that the breach could have a significant downstream impact on the U.S. healthcare sector.
Pattern of health-care supply-chain attacks
Craneware is the latest healthcare vendor to announce a cyberattack in an era that has seen many breaches of medical-device makers and hospital software suppliers.
Last week, the security firm Fortified Health Security said supply-chain risk management was one of the sector’s biggest challenges. The firm’s latest report found that healthcare providers identified six times more supply-chain risks in the first half of 2026 than they did in the first half of 2025, with nearly two-thirds of those risks involving critical or high-severity vulnerabilities.