The Hospital for Sick Children (SickKids) has disclosed a cybersecurity incident that exposed the personal information of some current and former employees, as well as job applicants. The Toronto-based pediatric hospital confirmed that the breach originated from a vulnerability in a third-party software application used by SickKids and other organizations.
According to SickKids, its clinical systems and patient records were not affected by the incident, and patient care continued without disruption. However, the hospital's public-facing Careers website was temporarily taken offline following the discovery of the breach. The Careers site has since been restored.
The incident resulted in unauthorized access to data belonging to current and former employees of SickKids, Boomerang (a SickKids-owned pediatric clinic), and the SickKids Foundation, in addition to SickKids job applicants. The hospital has not specified the exact categories of data exposed, the total number of individuals affected, or the date of the intrusion.
SickKids has initiated an investigation into the incident with the assistance of external cybersecurity experts. While the review of the impacted information is ongoing, the hospital is directly notifying individuals confirmed to be affected. Out of an abundance of caution, SickKids has also alerted all potentially impacted individuals and is offering 24 months of complimentary credit monitoring and identity protection services.
The hospital has not publicly identified the third-party vendor, the specific software application, or any associated CVE ID related to the vulnerability. The phrasing of the disclosure suggests a potential wider campaign targeting users of the same product.
This incident marks at least the third publicly known security event impacting SickKids in recent years. In December 2022, the hospital was hit by a ransomware attack attributed to the LockBit gang, which disrupted internal systems and caused delays in lab and imaging results. Although LockBit later issued an apology and provided a free decryptor, SickKids had already spent nearly two weeks restoring its systems independently.
In September 2023, SickKids was also among several Ontario healthcare providers affected by a data breach at a third-party organization that manages perinatal and child health data. That incident, which stemmed from the mass exploitation of the MOVEit Transfer zero-day vulnerability (CVE-2023-34362), exposed information on 3.4 million individuals, including names, home addresses, dates of birth, and health card numbers.






