SickKids Cybersecurity Incident Exposes Employee and Applicant Information
Toronto’s Hospital for Sick Children, commonly known as SickKids, has disclosed a cybersecurity incident that may have exposed the personal information of current and former employees, as well as job applicants.
The hospital said the incident was linked to a vulnerability in third-party software used by SickKids and other organizations. Clinical systems and patient records were not affected, while the hospital’s public recruitment website was temporarily taken offline.
SickKids recruitment website restored after data breach
SickKids announced the incident this week, stating that unauthorized access to employee-related information had occurred.
The hospital believes the breach was caused by a vulnerability in a third-party software application used by SickKids and other organizations. SickKids published additional details in a media statement.
The disclosure suggests that other users of the same software may also have been affected. However, SickKids has not identified the software vendor, application, or specific CVE associated with the vulnerability.
The hospital’s external recruitment website was briefly impacted but “has since been safely restored,” according to the statement.
SickKids confirmed that its clinical systems and patient information were not affected. Patient care continued as normal throughout the incident.
After discovering the unauthorized access, the hospital launched an investigation with assistance from external cybersecurity experts.
The investigation found that personal information belonging to current and former SickKids employees, Boomerang pediatric clinic employees, SickKids Foundation employees, and SickKids job applicants may have been compromised.
SickKids has not disclosed the types of information involved, the number of individuals affected, or when the breach occurred.
The investigation remains ongoing. Individuals confirmed to have been affected will be contacted directly by the hospital.
As a precaution, SickKids said it would notify anyone who may be involved in the incident. Identified individuals will also receive 24 months of complimentary credit monitoring and privacy protection services.
Recruitment websites are attractive targets for cybercriminals because applicants often submit names, home addresses, telephone numbers, employment histories, and, in some jurisdictions, government-issued identification details. Such information can be used for identity theft, fraud, and convincing social engineering attacks targeting healthcare employees.
SickKids has been targeted by cyberattacks before
This is not the first publicly known cybersecurity incident to affect SickKids in recent years.
In December 2022, the hospital suffered a ransomware attack that disrupted internal systems, telephone lines, and its website. The incident also caused delays in test and imaging results.
The LockBit ransomware group later issued an unusual public apology, claiming that the affiliate responsible had violated the group’s rules against encrypting healthcare organizations. LockBit also provided a free decryption tool, although SickKids had already spent approximately two weeks restoring its systems independently.
In September 2023, SickKids was also affected by a data breach involving a third-party organization with which it shared perinatal and pediatric health information. The incident resulted from the mass exploitation of the MOVEit Transfer zero-day vulnerability, tracked as CVE-2023-34362.
The MOVEit breach exposed information belonging to approximately 3.4 million people, including names, home addresses, dates of birth, and health card numbers.
Healthcare organizations continue to be among the most heavily targeted sectors by ransomware operators and data extortion groups.
Children’s hospitals are particularly attractive targets because they maintain decades of sensitive medical and personal records. Despite criminal groups’ claims that they avoid attacking healthcare organizations, hospitals remain frequent victims of cyberattacks and data breaches.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




