SickKids Hospital Discloses Cybersecurity Breach Affecting Employee and Applicant Data
The Hospital for Sick Children (SickKids) in Toronto has reported a cybersecurity incident exposing personal information of current and former employees, as well as job applicants. The breach originated from a vulnerability in a third-party software application used by the hospital and other organizations, though the vendor, specific software, and associated CVE remain undisclosed.
The hospital’s public-facing Careers website was temporarily taken offline but has since been restored. Clinical systems and patient records were unaffected, ensuring uninterrupted care. An investigation, supported by external cybersecurity experts, revealed that data belonging to employees of SickKids, its subsidiary Boomerang Pediatric Clinic, the SickKids Foundation, and job applicants may have been compromised. The exact categories of exposed data, the number of affected individuals, and the timeline of the intrusion have not been released.
As a precaution, SickKids has notified all potentially impacted individuals and is offering 24 months of complimentary credit monitoring and identity protection. Job application portals are frequent targets for cybercriminals due to the sensitive information they collect, including names, addresses, employment histories, and government identifiers valuable for identity fraud and social engineering attacks.
This incident marks the latest in a series of cybersecurity challenges for SickKids. In December 2022, the hospital suffered a ransomware attack that disrupted internal systems, phone lines, and lab services, though the LockBit gang later issued an apology and provided a decryptor. In September 2023, SickKids was also impacted by the mass exploitation of the MOVEit Transfer zero-day (CVE-2023-34362), exposing data on 3.4 million individuals.
Healthcare, particularly pediatric hospitals, remains a prime target for ransomware and data extortion groups due to the vast troves of sensitive records they maintain.
The Hospital for Sick Children cybersecurity rating report: https://www.rankiteo.com/company/the-hospital-for-sick-children
Boomerang Health powered by SickKids cybersecurity rating report: https://www.rankiteo.com/company/boomerang-health-powered-by-sick-kids
"id": "THEBOO1787308021",
"linkid": "the-hospital-for-sick-children, boomerang-health-powered-by-sick-kids",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Current and former employees, '
'job applicants',
'industry': 'Healthcare',
'location': 'Toronto, Canada',
'name': 'Hospital for Sick Children (SickKids)',
'type': 'Hospital'},
{'customers_affected': 'Employees',
'industry': 'Healthcare',
'location': 'Toronto, Canada',
'name': 'Boomerang Pediatric Clinic',
'type': 'Clinic'},
{'customers_affected': 'Employees',
'industry': 'Healthcare/Charity',
'location': 'Toronto, Canada',
'name': 'SickKids Foundation',
'type': 'Non-profit'}],
'attack_vector': 'Third-party software vulnerability',
'customer_advisories': '24 months of complimentary credit monitoring and '
'identity protection offered to affected individuals',
'data_breach': {'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Personal information (names, '
'addresses, employment histories, '
'government identifiers)'},
'description': 'The Hospital for Sick Children (SickKids) in Toronto has '
'reported a cybersecurity incident exposing personal '
'information of current and former employees, as well as job '
'applicants. The breach originated from a vulnerability in a '
'third-party software application used by the hospital and '
'other organizations. The hospital’s Careers website was '
'temporarily taken offline but has since been restored. '
'Clinical systems and patient records were unaffected.',
'impact': {'data_compromised': 'Personal information of employees and job '
'applicants',
'downtime': 'Temporary outage of Careers website',
'identity_theft_risk': 'High (government identifiers, employment '
'histories, etc.)',
'operational_impact': 'Clinical systems and patient records '
'unaffected',
'systems_affected': 'Careers website'},
'investigation_status': 'Ongoing',
'post_incident_analysis': {'root_causes': 'Third-party software '
'vulnerability'},
'references': [{'source': 'Cyber Incident Description'}],
'response': {'communication_strategy': 'Notification to potentially impacted '
'individuals',
'containment_measures': 'Careers website temporarily taken '
'offline',
'recovery_measures': 'Careers website restored',
'third_party_assistance': 'External cybersecurity experts'},
'title': 'SickKids Hospital Cybersecurity Breach Affecting Employee and '
'Applicant Data',
'type': 'Data Breach'}