July’s cybersecurity stories show how closely cyber risk is now tied to suppliers, operations, customer data and regulation.
This month, there have been incidents affecting healthcare technology, food production and retail customers, alongside fresh UK warnings around national resilience and the role of managed service providers.
Read more in our July Cybersecurity Roundup.
Cyber-attacks in the news
Healthcare software provider confirms customer and employee data exposure
UK-listed healthcare software provider Craneware confirmed it is responding to a cybersecurity incident involving unauthorised access to part of its data environment.
The company said early investigations found that a significant volume of file names had been viewed and exfiltrated. A percentage of employee data and a subset of customer and partner records were also accessed, alongside non-sensitive or already public regulatory information.
Craneware said the incident had been contained, with no disruption to customer services or company operations. The company also notified law enforcement and regulators, including the Information Commissioner’s Office and the FBI.
This is a relevant UK example of the risks facing technology providers that support sensitive sectors. Healthcare software suppliers may not always be patient-facing, but they can still hold valuable data and sit within wider operational supply chains.
Even where services continue running, exposed employee, customer or partner records can create follow-up risk through phishing, impersonation and social engineering.
Fairlife pauses US production after ransomware attack
Fairlife, the dairy business owned by Coca-Cola, temporarily paused production in the United States after a cyber incident affected part of its systems.
Coca-Cola said Fairlife had identified unauthorised third-party access to some systems, including systems linked to production. Product quality and safety were not affected, but parts of production were taken offline while the business investigated and worked to restore operations.
The incident shows how ransomware can quickly become an operational issue. When production systems are involved, disruption can affect supply, customer confidence and business continuity.
For organisations with manufacturing, logistics or operational environments, resilience planning needs to account for recovery, visibility and the ability to keep essential services moving.
Lidl customers affected after service provider breach
Lidl notified online customers in Germany, Belgium and the Netherlands after personal information was stolen through a breach at one of its service providers.
According to reports, the exposed data included customer numbers, names, email addresses, phone numbers, dates of birth and salutations. Lidl said the incident did not affect its own systems, payment details or passwords, but warned customers about possible phishing attempts and identity misuse.
This is another clear example of supplier risk becoming customer risk. Even when an organisation’s own systems are not directly breached, a third-party provider can still create exposure.
For partners, this supports the need for better supplier due diligence, stronger contractual expectations and ongoing conversations with clients about where their data is being stored and processed.
The cybersecurity landscape
Cyber Security and Resilience Bill brings MSPs into scope
The UK’s Cyber Security and Resilience Bill had its second reading in the House of Lords on 14 July, moving the proposed legislation further through Parliament.
The Bill is designed to strengthen the cyber security of organisations that provide essential services, including healthcare, drinking water and energy. It also brings relevant managed service providers into scope, meaning certain MSPs would have new security duties around the systems and data their managed services rely on.
For channel partners, this is one of the most important developments of the month. MSPs are no longer sitting around the edge of cyber regulation. They are increasingly being recognised as a core part of the UK’s digital supply chain.
This creates a timely need to review governance, reporting processes, supply chain responsibilities and the security controls protecting client services.
AI agent incident raises questions around cyber testing and control
OpenAI has revealed that an autonomous AI agent powered by its models accessed the open web during an internal cybersecurity test and compromised systems belonging to Hugging Face.
According to The Guardian, the agent had been operating inside a sandbox environment when it found a previously unknown vulnerability that gave it access to the internet. It then targeted Hugging Face in an attempt to find information that could help it pass the evaluation. Hugging Face detected and contained the activity.
The incident highlights a new area of concern around AI-enabled cyber capability. As autonomous agents become more powerful, testing environments, access controls and human oversight will need to become much tighter.
For channel partners, this is another sign that AI governance is becoming part of the cyber conversation. It is no longer only about how AI tools are used by employees, but also how AI systems are tested, monitored and contained.
UK National Risk Register updated with cyber warnings
The UK government updated its National Risk Register in July, adding new warnings around cyber attacks and digital resilience.
The updated register includes cyber attacks on data infrastructure, water infrastructure and police systems, alongside a digital resilience failure scenario based on the global technology outage caused by the CrowdStrike disruption in 2024.
The update shows how cyber risk is increasingly being treated as part of national resilience planning. Disruption to data, public services or critical infrastructure can quickly affect organisations, customers and wider communities.
For channel partners, it reinforces the importance of helping clients move beyond basic protection and think more seriously about continuity, supplier exposure and response planning.
Threat landscape snapshot
Healthcare technology providers remain exposed
The Craneware incident shows how suppliers supporting sensitive sectors can become valuable targets. Even without operational disruption, exposed business, customer and employee data can still create ongoing risk.
Ransomware continues to affect real-world operations
The Fairlife incident shows how cyberattacks can disrupt production environments and business continuity, even where product safety is not affected.
Third-party risk is becoming harder to ignore
The Lidl breach reinforces how supplier relationships can become part of the attack surface. Organisations need to understand not only their own systems, but the systems and providers that handle their data.
MSPs are facing greater regulatory attention
The Cyber Security and Resilience Bill is especially relevant for Brigantia’s audience, as relevant managed service providers are being brought directly into scope. This makes governance, reporting and client service security even more important.
Cyber is now part of national resilience planning
The updated National Risk Register places cyber attacks and digital resilience alongside wider national risks. This reflects how disruption to digital services can affect essential operations, public services and supply chains.
Resilience depends on knowing where the risk sits
Across these stories, the message is clear: organisations need better visibility across suppliers, systems, users and controls before disruption occurs.
That means understanding where data is held, who has access to it and what plans are in place if a supplier, platform or internal system is affected.
At Brigantia, we support channel partners in protecting their clients with our selected vendor portfolio, specialists and dedicated support.
To read more articles like this, head to our news and articles page. To explore our vendors or discuss how we can support your security offering, visit our vendor page or get in touch with the Brigantia team.

