SickKids Hospital Hit by Second Cyberattack, Exposing Employee Data
Canada's largest pediatric health center, **The Hospital for Sick Children** (SickKids), has announced a new cybersecurity incident leading to the exposure of current and former employee personal information. This marks the second significant cyberattack against the institution since a major ransomware incident in 2022.
# SickKids Hospital Suffers Second Cyberattack, Employee Data Exposed
**The Hospital for Sick Children** (SickKids), Canadaβs leading pediatric health center, has disclosed a recent cybersecurity incident impacting the personal information of its current and former employees, as well as job applicants and staff from affiliated organizations like the **SickKids Foundation**. The hospital believes the data theft is linked to a third-party software application.
## Incident Details and Impact
The cyberattack briefly disrupted the hospitalβs careers website, prompting an immediate investigation. While **SickKids** has not specified the exact types of employee data compromised or the precise timing of the incident, it confirmed that clinical systems and patient information were not affected.
Impacted individuals have been notified and offered two years of credit monitoring services to mitigate potential risks.
## A Troubling Pattern: Previous Ransomware Attack
This latest breach follows a severe ransomware incident that crippled **SickKids** in December 2022, just before the Christmas holiday. That attack, which took weeks to recover from, significantly impacted critical systems including pharmacy operations, diagnostic imaging, and internal timekeeping.
In an unusual turn, the ransomware group responsible for the 2022 attack, later identified as **LockBit**, issued an apology, provided a free decryptor, and claimed to have fired the affiliate responsible for targeting the hospital.
## Broader Healthcare Sector Under Siege
**SickKids** is not alone in facing recent cyber threats. This disclosure comes alongside notices from other major healthcare organizations. **Baylor Genetics** recently reported a data leak from June, compromising medical testing information, lab results, health insurance details, and Social Security numbers. Similarly, electronic health records provider **CareCloud** disclosed a March cybersecurity incident affecting approximately 3.7 million individuals.
The repeated targeting of healthcare institutions underscores the persistent and evolving threat landscape facing the sector, emphasizing the critical need for robust cybersecurity defenses and third-party risk management.