SickKids Hospital Discloses Employee Data Breach Stemming from Third-Party Software Flaw
The Hospital for Sick Children (**SickKids**) in Toronto has announced a cybersecurity incident that exposed the personal information of current and former employees, as well as job applicants. The breach is attributed to a vulnerability within a third-party software application, though patient data and clinical systems remain unaffected.

**SickKids** disclosed this week that a "cybersecurity incident" resulted in unauthorized access to employee data. The hospital's public-facing Careers website was temporarily taken offline following the discovery.
### Third-Party Software Vulnerability Identified
The hospital attributes the breach to a flaw in a third-party software application used by **SickKids** and other organizations, according to a [media statement](https://www.sickkids.ca/en/news/archive/2026/SickKids-employee-information-impacted-by-cybersecurity-incident/). While the specific vendor, application, or **CVE** has not been named, the framing suggests a potentially wider campaign targeting users of the same product.
The external Careers website has since been safely restored. Crucially, **SickKids** has confirmed that clinical systems and patient information were not affected, ensuring patient care continued without disruption.
### Investigation and Data Impact
Upon learning of the incident, **SickKids** launched an investigation with the assistance of external cybersecurity experts. The findings indicate that personal information belonging to current and former employees of **SickKids**, **Boomerang** (a **SickKids**-owned pediatric clinic), and **SickKids Foundation** employees, along with **SickKids** job applicants, may have been exposed.
The hospital has not yet specified the categories of data involved, the total number of affected individuals, or the precise timeline of the intrusion. The review of impacted information is ongoing, with confirmed affected individuals to be notified directly.
Out of an abundance of caution, **SickKids** has alerted everyone potentially involved and is offering 24 months of complimentary credit monitoring and identity protection services.
Job application portals are particularly attractive targets for data thieves. They often contain sensitive personal details such as full names, home addresses, phone numbers, and employment histories, which can be leveraged for identity fraud or sophisticated social engineering attacks against hospital staff.
### A History of Incidents
This is not the first publicly reported security incident to impact **SickKids** in recent years. In December 2022, the hospital was hit by a ransomware attack attributed to the **LockBit** gang. This incident disrupted internal systems, phone lines, and caused delays in lab and imaging results. **LockBit** later issued a rare public apology and provided a free decryptor, though **SickKids** had already spent nearly two weeks restoring its systems.
In September 2023, **SickKids** was also among the Ontario healthcare providers affected by a data breach at a third-party organization that handles perinatal and child health data. This incident, stemming from the mass exploitation of the **MOVEit Transfer** zero-day (**CVE-2023-34362**), exposed information on 3.4 million people, including names, home addresses, dates of birth, and health card numbers.
The healthcare sector remains a prime target for both ransomware and data extortion groups. Pediatric hospitals, in particular, hold decades of sensitive records, making them attractive to attackers despite any claimed ethical boundaries by criminal operations.