Decoding the world of cybersecurity

· ·

Craneware resets outlook after cyber incident

Craneware has reset FY27 revenue expectations to about $185 million while remediation, customer notification, and regulatory work continue after July’s data breach.

Craneware resets outlook after cyber incident
Summary
  • Craneware confirms data was exfiltrated from a subset of its environment, although customer services and core operations were not disrupted.
  • Employee information and a subset of customer and partner records were among the material accessed.
  • The company has reset FY27 revenue expectations to about $185 million while saying the incident’s ultimate financial consequences remain uncertain.

A cyber incident disclosed by healthcare software provider Craneware in July has moved into its financial planning, with the company resetting near-term revenue expectations while it continues customer notifications, regulatory work, and remediation.

Craneware, which is listed on London’s AIM market and supplies financial-performance software to US healthcare organisations, said in its full-year results that the intrusion did not disrupt customer services or core operations.

An independent investigation has verified that its systems are secure, fully operational, and free of indicators of continuing compromise, according to the company. The investigation nevertheless established that a significant volume of file names was viewed and data was exfiltrated.

Craneware currently assesses a large proportion of the affected information as non-sensitive or already publicly available regulatory data. It also confirmed that some employee information and a subset of customer and partner records were accessed and taken.

The company is still determining the precise nature and scope of the information and identifying affected parties. Notifications to customers and regulators are continuing, with the UK Information Commissioner’s Office and the US Federal Bureau of Investigation among the bodies notified.

The incident occurred after the end of Craneware’s 2026 financial year, so it did not cause the company’s weaker-than-expected performance during that period. FY26 revenue was $206 million, broadly flat on the previous year, while adjusted EBITDA increased 3% to $67.1 million.

The security incident has, however, added uncertainty to the outlook. Craneware said it is taking a more prudent view of FY27 revenue and has reset expectations to approximately $185 million, equivalent to its annual recurring revenue at the end of June.

The company has not attributed that entire adjustment to the incident. Its results also describe trading pressures around the US 340B drug-pricing programme and delayed revenues. The board said its planning assumptions reflect both the FY26 outcome and uncertainty arising from the cyber incident.

That distinction is important when measuring cyber impact. Financial consequences rarely arrive as a single, easily isolated line item. For a software provider, an incident can influence renewal discussions, new sales, legal costs, insurance, remediation work, regulatory engagement, and the amount of management attention diverted from ordinary operations.

Craneware said the full financial outcome is not yet quantifiable, including the effect on future customer engagement. It expects remediation and related legal and regulatory activity to span several financial periods.

The company’s exposure is amplified by the sector it serves. Healthcare software suppliers sit inside a network of hospitals, financial systems, regulatory datasets, integrations, and long-term commercial relationships. Even where clinical services remain unaffected, a data incident can create extensive assurance work for customers that need to understand what information moved through a supplier and whether their own obligations are triggered.

The disclosure also provides a more useful measure of incident consequence than initial containment alone. Craneware was able to keep core services available, and external specialists found no continuing compromise, but the commercial and regulatory work continues months after the immediate intrusion ended.

Craneware remains profitable and says recurring revenue, customer retention, liquidity, and cash generation provide resilience while it works through the incident. The next material measure will be whether customer engagement, renewal rates, and remediation costs diverge from the assumptions now built into its FY27 plan.

×