Skip to content
Vulnerability exploitContained

SickKids employee data breach (third-party software flaw)

Toronto's Hospital for Sick Children (SickKids) disclosed that a vulnerability in a third-party software application exposed personal information of current and former employees and job applicants, while clinical systems and patient data were unaffected.

Victim
The Hospital for Sick Children (SickKids)

On 20 August 2026, The Hospital for Sick Children (SickKids) β€” a leading pediatric hospital and research center in Toronto β€” disclosed that a cybersecurity incident had resulted in unauthorized access to the personal information of some of its current and former employees. The hospital attributed the breach to a vulnerability in a third-party software application used by SickKids and other organizations; neither the application nor its vendor was named.

Crucially, SickKids said clinical systems and patient information were not affected and that patient care continued as usual. The incident temporarily affected the hospital's external Careers website, which was subsequently taken down for remediation and safely restored.

What happened

Working with external cybersecurity experts, SickKids determined that personal information of current and former employees β€” including staff of Boomerang Health (a SickKids-owned pediatric clinic) and the SickKids Foundation β€” as well as job applicants, may have been affected. The hospital did not disclose the specific categories of data accessed or the number of people involved, saying that individuals confirmed to be affected would be notified directly.

Potentially impacted individuals were alerted and offered 24 months of complimentary credit monitoring and identity-protection services. The breach came less than four years after a separate, higher-profile 2022 ransomware incident at the hospital, though the two events are unrelated.

Impact

  • Personal information of current and former employees and job applicants, across SickKids, Boomerang Health and the SickKids Foundation, may have been exposed.
  • Clinical systems and patient data were not affected; patient care continued normally.
  • The external Careers website was temporarily disrupted; affected individuals were offered 24 months of credit and identity monitoring.

Why it matters

The SickKids breach highlights how third-party software vulnerabilities can expose sensitive data even when a hospital's own clinical systems remain secure. Recruitment and HR platforms hold identity documents and personal details for staff and applicants β€” a data set attractive to fraudsters and often managed outside a hospital's core security perimeter. The incident reinforces the need for healthcare organizations to inventory and assess the security of every third-party application touching employee and applicant data, not just clinical systems.

Timeline

  1. SickKids publicly discloses a cybersecurity incident affecting personal information of current and former employees.

  2. Reporting details that a third-party software vulnerability was exploited and that the external Careers website was temporarily affected and then restored.

Sources

  1. sickkids.cahttps://www.sickkids.ca/en/news/archive/2026/SickKids-employee-information-impacted-by-cybersecurity-incident
  2. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/sickkids-data-breach-exposes-employee-and-job-applicant-info/
  3. theregister.comhttps://www.theregister.com/cyber-crime/2026/08/21/sickkids-childrens-hospital-bandages-up-careers-website-after-intruder-breaks-in/5291098
  4. cybernews.comhttps://cybernews.com/news/sickkids-breach-exposes-employee-and-applicant-data/

Related incidents

RansomwareResolved

SickKids hospital ransomware attack

Toronto's Hospital for Sick Children was hit by a ransomware attack over the December 2022 holidays that delayed lab and imaging results; in a rare move, the LockBit gang apologized, blamed a rogue affiliate, and released a free decryptor.

Victim
The Hospital for Sick Children (SickKids)
EspionageContained

UNC6508 PRC-nexus medical & defense research espionage campaign

Google's Threat Intelligence Group disclosed that PRC-nexus actor UNC6508 spent more than a year inside U.S. and Canadian medical, academic and military-health research environments, compromising legacy REDCap servers, deploying custom INFINITERED malware and abusing Google Workspace email compliance rules to silently exfiltrate research and defense data.

Victim
U.S. and Canadian medical, academic and military-health research institutions