Craneware shares fall another 24% amid cyber impact

Craneware CEO Keith Neilson

Shares of Edinburgh-based US healthcare software firm Craneware plc fell another 23% on Monday after it published annual results and updated investors on the potential financial impact impact of a cyber security attack in June.

On July 20, 2026, Craneware suffered a cyber security attack involving unauthorised access to a subset of its data environment.

In June 2025, Craneware confirmed it rejected a £26.50 per share takeover proposal from Bain Capital that would have valued the Edinburgh company at about £939.4 million.

The Edinburgh firm’s shares have since fallen more than 50% to around £10.33 to slash Craneware’s stock market value to roughly £350 million.

Craneware said its revenue for the year to June 30 was “stable” at $206 million, statutory profit before tax increased 7% to $25.8 million, and its proposed total dividend was consistent with the prior year of 32p per share.

However, Craneware said in its outlook: ” … the immediate impact of the Cyber security incident has been contained; however, the full financial outcomes are yet to be quantified, including the impact of future customer engagement.

“While the board remains confident in the long-term outlook for the group and the growth opportunities, it is taking a prudent view of its revenue expectations in FY27, resetting them to the equivalent of the company’s annual recurring revenue of c.$185m.”

Craneware CEO Keith Neilson said: “Delivering growth consistently over an 18-year period as a public company is rarely straightforward. FY26 was challenging and growth was below our expectations.

“We responded quickly to the evolving 340B environment and the increasingly onerous drugs manufacturers’ requirements by launching the first of a family of software solutions designed to help customers manage these new 340B requirements.

“Recent market developments indicate that 340B conditions should become progressively more supportive for these new offerings through FY27, particularly in the second half, although the timing remains dependent on regulatory clarity and customer adoption.

 “The cyber incident has led us to reset our near-term financial expectations to provide certainty to stakeholders, but it does not change our confidence in the group’s long-term opportunity.

“In FY27, our priorities are to renew long-term customer contracts, expand recurring revenue through sales to new and existing customers, ensure our cost base is suitably sized and maintain strong cash generation, providing a platform for growth in FY28 and beyond. 

“Looking ahead, our financial resilience, deep integration into core customer workflows and proprietary data provide a strong long-term foundation for sustained value generation, as we support our customers in transforming the business of healthcare.”