Medical software provider Craneware hit by hackers, customer data stolen
British medical software provider Craneware announced on Monday that some of its data environments experienced unauthorized access, with hackers stealing a large number of files involving employee data and some customer and partner records. The company stated that most of the data is non-sensitive or publicly available regulatory data, but the investigation is still ongoing. Craneware provides software to more than 2,000 healthcare institutions and nearly 10,000 clinics and retail pharmacies worldwide. This incident once again highlights the severe situation of supply chain attacks in the healthcare industry.

A major supplier of software to the healthcare industry disclosed on Monday (February 23, 2026) that its systems had been hacked and a large number of files stolen. The company said the incident could have a broad impact on downstream customers.
British software company Craneware reported the "cybersecurity incident" in a regulatory filing to the London Stock Exchange, saying that "a portion of its data environment" had been subject to "unauthorized access," resulting in the theft of a "significant" number of files, including "employee data and some customer and partner records." Craneware develops software that primarily helps healthcare organizations track financial performance and manage compliance requirements.
In a statement, Craneware said: "The current assessment is that a large portion of the data involved is non-sensitive or already publicly available regulatory data." However, the company also noted that an investigation involving internal IT staff and third-party cybersecurity firms is still ongoing.
Although Craneware is a British company, its website markets its products primarily to U.S. healthcare organizations and lists Microsoft and the National Rural Health Association, among other U.S. industry associations and technology companies, as strategic partners.
According to Craneware's website, more than 2,000 healthcare organizations and nearly 10,000 clinics and retail pharmacies use its products. This means the data breach could have significant downstream ripple effects on the U.S. healthcare industry.
Supply chain attacks in the healthcare industry are on the rise
Craneware is the latest healthcare industry supplier to announce a cyberattack in recent times. In recent years, medical device manufacturers and hospital software suppliers have frequently been targets of hackers, and supply chain risk has become one of the major challenges in the field.
Last week, security firm Fortified Health Security released a report pointing out that supply chain risk management is one of the biggest challenges facing the healthcare industry. The report found that in the first half of 2026, the number of supply chain risks identified by healthcare organizations was six times that of the same period in 2025, with nearly two-thirds of the risks involving severe or high-severity vulnerabilities.