Craneware (AIM:CRW) reported it identified and is responding to a cyber security incident involving unauthorised access to a subset of its data environment.
The AIM-listed healthcare financial performance solutions provider activated its incident response plan, appointing external cyber security and forensic specialists to investigate alongside its internal IT team. The company said the incident has been contained and that external specialists have confirmed no residual indicators of compromise remain in its systems.
Craneware notified relevant regulators and law enforcement, including the UK's Information Commissioner's Office and the US Federal Bureau of Investigation.
Investigations so far show a significant volume of file names were viewed and exfiltrated, though the company assesses much of the data as non-sensitive or already publicly available regulatory information.
A percentage of Craneware employee data, along with a subset of customer and partner records, was accessed and exfiltrated.
The company said there has been no disruption to customer services or operations.
It is continuing to assess the scope of the data involved and working with advisers to identify affected parties ahead of further notifications to relevant authorities.
News Intelligence what this means for the company
Craneware has disclosed a cyber security incident involving unauthorised access to a subset of systems and exfiltration of employee, customer and partner data, though the company reports no service disruption and says much of the exfiltrated data is non-sensitive or already public. The incident arrives three weeks after a 24.9% share collapse triggered by a profit warning, compounding investor concern at a moment when the company is already guiding flat adjusted EBITDA and citing timing headwinds in its core 340B drug-pricing business.
The breach does not appear to have disrupted operations or revenue recognition, but it introduces regulatory and reputational risk at a time when Craneware is already executing against depressed FY26 guidance. The scope of customer and partner data exfiltration, and any resulting notification obligations or remediation costs, remain under investigation and could weigh on near-term cash generation and investor confidence.
Insights assembled by AI. Editor-reviewed and grounded in tickstock’s coverage and proprietary knowledge graph.
Content is for informational purposes only, not financial advice.