Craneware plc has disclosed a Craneware data breach after detecting unauthorized access to a portion of its data environment. The company confirmed on 20 July 2026 that it is investigating the incident with the support of external cybersecurity and forensic experts.
Although the cyberattack on Craneware resulted in data being viewed and exfiltrated, the company said the incident has been contained and has not disrupted customer services or business operations.
Craneware Cyberattack Contained, Investigation Underway
According to the company’s official notice, the Craneware cyberattack prompted the activation of its incident response plan immediately after the unauthorized access was identified. The Board appointed external cybersecurity and forensic specialists, who are working alongside Craneware’s internal IT team and retained security providers to determine the full scope of the incident.
The company stated that investigators have found no remaining indicators of compromise within its systems. Despite the data breach at Craneware, normal operations have continued without interruption.
Data Breach at Craneware Exposed Employee and Customer Records
Initial findings indicate that attackers viewed and exfiltrated a significant volume of file names. Craneware’s current assessment suggests that much of the affected information consists of non-sensitive or publicly available regulatory data. However, the investigation has also confirmed that a percentage of employee data, along with a subset of customer and partner records, was accessed and exfiltrated during the Craneware data breach.
The organization is continuing to examine the precise nature and extent of the compromised data. It is also working with advisers to identify affected individuals and organizations, prepare notifications where necessary, and meet all applicable regulatory obligations. Craneware added that it will provide further updates to the market as additional information becomes available.
As part of its response to the data breach at Craneware, the company has notified relevant regulators and law enforcement agencies. These include the UK’s Information Commissioner’s Office (ICO) and the US Federal Bureau of Investigation (FBI).
Craneware to Notify Affected Parties as Assessment Continues
In its official announcement, Craneware said: “The incident has been contained, and there has been no disruption to customer services or to the Company’s operations. The external specialists have confirmed that there are no residual indicators of compromise arising from the cybersecurity incident in the Company’s systems.”
The company further stated: “Investigations so far have established that a significant volume of file names were viewed and exfiltrated. The current assessment is that a large element of the data involved is non-sensitive or already public regulatory data. A percentage of Craneware employee data as well as a subset of customer and partner records, have been accessed and exfiltrated.”
The notice also stated: “This announcement contains inside information as stipulated under the UK version of the Market Abuse Regulation No 596/2014, which is part of English Law by virtue of the European (Withdrawal) Act 2018, as amended. On publication of this announcement via a Regulatory Information Service, this information is considered to be in the public domain.”
While the investigation into the cyberattack on Craneware remains ongoing, the company said it will continue assessing the impact of the cyberattack and issue further updates as appropriate.

