LIVE · cybersecurity feed
Live wire
ransomware

Canada’s Hospital for Sick Children attacked by cybercriminals again as employee data stolen

The Hospital for Sick Children — which was hit in a ransomware incident in 2022 that disabled some of its systems — released a statement on Thursday warning of a data theft incident they believe is tied to a third-party software application.

zeroday.news ·

The Hospital for Sick Children (SickKids) in Toronto, Canada, has confirmed a recent cybersecurity incident that resulted in the theft of personal information belonging to current and former employees. This marks the second significant cyberattack against the institution, following a ransomware incident in 2022.

SickKids issued a statement on Thursday, indicating that the data theft is believed to be linked to a third-party software application. The incident also briefly disrupted the hospital's careers website. The investigation suggests that the stolen data likely pertains to current and former employees, job applicants, and staff of affiliated organizations, including the SickKids Foundation. The specific types of employee data compromised have not been detailed. Crucially, the hospital confirmed that no clinical systems or patient information were affected by this breach.

Individuals potentially impacted by the incident have been notified and offered two years of credit monitoring services.

This latest attack follows a 2022 ransomware incident that severely impacted the hospital's systems during the Christmas holiday period. That previous attack, which affected pharmacy systems, diagnostic imaging results, and internal staff timekeeping, took several weeks for the hospital to recover from. The group responsible for the 2022 attack later issued an apology, provided a free decryptor, and claimed to have terminated the affiliate who targeted SickKids.

The SickKids incident occurs amidst a series of recent cybersecurity breaches disclosed by other healthcare organizations. Baylor Genetics reported a June data leak involving medical testing information, laboratory test results, health insurance details, and Social Security numbers. Additionally, electronic health records provider CareCloud announced a March cybersecurity incident that affected 3.7 million individuals.

ransomwarehealthcare
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug

Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification. The post In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug appeared first on SecurityWeek.

security

Lawmakers seek watchdog review of federal hacking of Americans

Sen. Ron Wyden and Rep. Greg Casar want a GAO probe on the government’s use of spyware and other sophisticated hacking tools and authorities. The post Lawmakers seek watchdog review of federal hacking of Americans appeared first on CyberScoop.

ai

Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini

Researchers say the new ‘Cryptographic Context Injection’ technique conceals malicious instructions until they are decrypted inside a trusted execution environment. The post Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini appeared first on SecurityWeek.

phishing

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

Researchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions revoked. The post New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets appeared first on SecurityWeek.

security

Zombie Card: An expired Visa credit card can be used for purchases

Scientific research showed that the expiration date on some Visa credit cards can be manipulated in so-called Zombie Card attacks.

security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.