Skip to content
Rush Commerce
Software & Dev3 min read

Craneware breach: your vendor's vendor holds your data

Hackers stole data from Craneware, billing software behind 2,000+ US hospitals. Why fourth-party risk is the exposure most small businesses never map.

On July 20, 2026, Edinburgh-based Craneware told the London Stock Exchange that attackers had stolen a significant volume of data from its systems. Craneware isn't a household name. It's the billing, pricing, and pharmacy software running behind more than 2,000 U.S. hospitals and close to 10,000 clinics and retail pharmacies. Almost nobody affected by this breach has ever signed a contract with Craneware. That's the whole point.

What actually happened

Per the company's LSE statement, a large number of file names were viewed and copied off its network. Craneware characterized much of the material as non-sensitive or already-public regulatory data, but acknowledged that a percentage of employee data and a subset of customer and partner records were accessed and exfiltrated. It says the intruders "appear to have been expelled," with the investigation still running.

What's missing from the disclosure is most of it. TechCrunch reports that no group has claimed responsibility and it's unclear whether a ransom was demanded. The Record notes the company hasn't clarified whether patient information was among the stolen data, hasn't given a breach or detection date, and hasn't notified affected organizations — it says it will, once it knows what was taken. Founded in 1999, Craneware is a company most of its downstream data subjects have never heard of.

Why fourth-party risk matters for your business

Swap "hospital" for whatever you run. You vet your vendors. Do you know who they run on? Your payroll provider's data warehouse. Your booking tool's SMS gateway. Your e-commerce platform's fraud-scoring service. Your customer records are sitting in systems two and three hops out from any contract you've read, and when one of those is breached you learn about it from a stock exchange filing written by a company you can't call.

You can't audit the whole chain. You can do three things that are cheap and actually work.

Map it once. For every system holding customer or employee data, write down the vendor, what data it holds, and which subprocessors it names in its DPA. Most SaaS vendors publish that list. Read it once and you've found your real blast radius.

Cut what you send. The most defensible record is the one you never transmitted. If your scheduling tool doesn't need dates of birth, stop syncing them.

Own the primary copy. When your data lives in a system you control and syndicates outward, a vendor breach is a scoping exercise, not an archaeology dig. When the vendor holds the only copy, you're waiting on their timeline.

Key takeaways

  • Craneware disclosed a breach via LSE filing on July 20, 2026; it serves 2,000+ US hospitals and ~10,000 clinics and pharmacies
  • Employee data plus a subset of customer and partner records were exfiltrated; attackers appear to have been removed
  • No breach date, no patient-data confirmation, no notifications yet, and no group has claimed responsibility
  • Downstream organizations had no direct relationship with the breached vendor — that's fourth-party risk
  • The operator move: map your subprocessors, minimize what you transmit, and keep the primary copy in a system you own

Do you know where your customer data actually lives? We map the vendor chain and rebuild the integrations so your business owns the primary record instead of renting it. Let's map yours.

Sources: TechCrunch, The Record.

  • #data-breach
  • #vendor-risk
  • #third-party-risk
  • #healthcare
  • #security
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.