Cybersecurity

Breach Exposes Data of Employees and Job Applicants at Canadian SickKids Hospital

Toronto’s SickKids children’s hospital announced that a vulnerability in third-party software led to unauthorized access to personal information belonging to some current and former employees and job applicants. The hospital said its clinical systems and patient records were not affected, while the scope of the incident remains under investigation.

2026-08-21
4 min read
12 views
فريق تحرير certi.news
Breach Exposes Data of Employees and Job Applicants at Canadian SickKids Hospital

The Hospital for Sick Children (SickKids) in Toronto disclosed a cybersecurity incident that resulted in the exposure of personal information belonging to some of its current and former employees, as well as job applicants. The hospital linked the incident to a vulnerability in a third-party software application, without disclosing the vendor’s or application’s name or the vulnerability number (CVE).

The hospital confirmed that its clinical systems and patient records were not affected and that medical care continued as usual. The public careers website was temporarily taken offline while the incident was addressed, before being brought back online after it was secured, according to a hospital statement.

Investigation Ongoing and Data Scope Undetermined

SickKids launched an investigation with the assistance of independent cybersecurity experts after discovering the incident. Preliminary findings indicate that personal data belonging to current and former SickKids employees, employees of the hospital-owned Boomerang Clinic, SickKids Foundation employees, and job applicants may have been exposed.

The hospital has not yet determined the types of data that were accessed, the number of people affected, or the period during which the intrusion occurred. A review of the affected information is still underway, and individuals confirmed to have been affected will be notified directly. SickKids said it alerted everyone who might be involved as a precaution and is also providing them with free credit monitoring and identity theft protection services for 24 months.

Why Does Employment Data Matter?

Employment portals typically contain a wide range of personal data, such as names, addresses, phone numbers, and employment history, and in some countries they may include government-issued identifiers. This information can therefore be used for identity fraud or to prepare more convincing phishing and social engineering attempts targeting hospital workers.

SickKids’ reference to a vulnerability in software used by other organizations suggests that the incident could be part of a broader campaign against users of the same product, but the hospital has not confirmed this and has not identified the product, vendor, or vulnerability involved. Accordingly, it is not yet possible to estimate how far the incident may have spread beyond SickKids.

Previous Record of Healthcare-Related Incidents

The new disclosure follows previous security incidents affecting the hospital or organizations that work with it. In December 2022, SickKids was hit by a ransomware attack that disrupted internal systems, phone lines, and the hospital’s website, and also delayed laboratory test results and medical imaging. The LockBit gang later announced that the attack violated its rules concerning the encryption of medical institutions and provided a free decryption tool after the hospital spent nearly two weeks restoring its systems on its own.

In September 2023, SickKids was among the healthcare providers in Ontario affected by a breach at an external organization with which it shared maternal and child health data. That incident resulted from the widespread exploitation of the MOVEit Transfer vulnerability known as CVE-2023-34362 and exposed the information of 3.4 million people, including names, addresses, dates of birth, and health card numbers.

The sequence of these events shows that healthcare institutions can face risks through their direct systems or through the software and external organizations connected to them, even when patient records and clinical operations remain outside the scope of the specific incident.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news