decrypted · 22 july 2026 · ransomware and cybercrime · vulnerabilities and patching · surveillance and privacy

A hospital billing vendor's breach, and the 147 million records it inherited

Craneware, an Edinburgh firm listed on London's AIM market, told the stock exchange on Monday that hackers had spent time inside its systems and left with a "significant volume" of file names, some employee data, and a slice of customer and partner records. Craneware supplies billing and revenue software to roughly two thousand American hospitals and pharmacies, and has told the Information Commissioner's Office and the FBI. No extortion gang has claimed the attack, and the company says the intrusion is contained. The breach itself is depressingly routine for 2026. What makes it worth five minutes is what was sitting behind the door: through a 2021 acquisition, Craneware holds 147 million patient records built up over two decades, on a system never designed, from the ground up, to be their custodian.

What Craneware has said, and not said

The company's own account is thin, which is normal this early: a "significant volume" of data was viewed and taken, mostly file names it says were non-sensitive, plus employee records and "a selection" of customer and partner data. It has not said how many people are affected, how attackers got in, how long they were inside, or whether any group is holding data to ransom. Craneware's chief growth officer told TechCrunch only that the investigation continues. That reticence is standard while forensics run, but the one fact UK readers can bank on this week is the one Craneware volunteered unprompted: this is a billing and analytics vendor sitting on a patient data set roughly twice the size of the UK's population, inherited rather than built.

The design question nobody asked in 2021

Secure by Design says a system's blast radius should match what it needs to do its job, not what it happens to have accumulated. A billing platform needs enough patient data to raise an invoice and reconcile a claim. It does not obviously need, in one exfiltratable place, employee HR records sitting alongside customer files and years of patient history from an acquired subsidiary. Acquisitions are where this scope creep hides best: Sentry's records became Craneware's in 2021, and the harder work of re-segmenting that data, re-scoping who can reach it, and deciding what no longer needs retaining, rarely survives the integration timetable. It is unglamorous work with no feature to show for it, which is exactly why boards should be asking whether it happened, not assuming it did because the deal closed years ago. For any UK company that has bought its way into holding data it didn't design for, that is this week's homework, not Craneware's alone.

Also this week

A fourth hole in the same AI platform. CISA added CVE-2026-0770, a critical, unauthenticated remote code execution flaw in the Langflow AI workflow builder, to its exploited vulnerabilities list on 21 July, with a fix deadline of 24 July. It is Langflow's fourth actively exploited flaw this year, this one letting anyone reach the platform's validate endpoint and run code as root, no login required. Langflow sits in front of production databases, cloud credentials and API keys for the pipelines built on it, so each unauthenticated hole is a hole into whatever it automates. A platform that keeps shipping the same class of bug is telling you about its design process, not just its patch cadence.

Brussels tightens the rules on scraping for AI training, London already has. The European Data Protection Board adopted guidelines on 8 July setting out when scraping personal data to train generative AI models has a lawful basis, insisting on data minimisation, source vetting and special protection for sensitive categories, with consultation open until 30 October. The UK's Information Commissioner's Office already takes a similar line: legitimate interest is the only basis on offer, and it has to survive a genuine necessity test, not just be the box a developer ticked. For any UK organisation feeding scraped data into a model, the message from both regulators is the same: prove you needed it, not that you could get it.

A hot fortnight for cloud resilience. Google Cloud's own status page confirms an electrical fault at its europe-west4 site in the Netherlands knocked out utility power and cooling on 15 July, and engineers spent nearly fifteen hours bringing VMware Engine, NetApp Volumes and Bare Metal Solution back as ambient heat forced a protective shutdown. Redundant cooling failing all at once, in the same summer the UK has logged more 30-degree days than the whole of 1976, is a design assumption worth revisiting, not a freak event. UK organisations leaning on a single EU region for data residency should treat this as a resilience test they didn't ask for.

Sources

Thinking through data minimisation after an acquisition, or how your systems would hold up to a Secure by Design review? Get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.