Personal Data of SickKids Employees and Job Applicants Exposed in Cybersecurity Incident
The Hospital for Sick Children (SickKids) has disclosed a cybersecurity incident that has exposed the personal information of current and former employees, as well as job applicants. The breach occurred due to a flaw in third-party software used by the hospital, which also affects other organizations.
According to SickKids, the vulnerability allowed unauthorized access to employee data, although clinical systems and patient records were not affected. The hospital’s public-facing Careers website was temporarily pulled offline, but has since been restored. An investigation into the incident is ongoing, with the help of outside cybersecurity experts.
The scope of the breach is still being reviewed, but it appears that personal information belonging to employees of SickKids, its owned pediatric clinic Boomerang, and the SickKids Foundation, as well as job applicants, may have been exposed. The hospital has not disclosed what categories of data were involved or how many people are affected.
In a statement, SickKids emphasized that patient care continued as usual during the incident, and that clinical systems and patient records remained secure. However, the breach highlights the importance of robust cybersecurity measures in protecting sensitive information. Job application portals, which often collect comprehensive personal data from applicants, can be particularly vulnerable to attacks.
This is not the first publicly known security incident to affect SickKids in recent years. In 2022, the hospital was hit by a ransomware attack that disrupted internal systems and caused delays in lab and imaging results. The hospital also suffered a breach at a third-party organization it shares perinatal and child health data with in 2023, which exposed information on over 3.4 million people.
Healthcare remains one of the most heavily targeted sectors for both ransomware crews and data extortion groups. Pediatric hospitals like SickKids often sit on decades’ worth of sensitive records, making them attractive targets for attackers. Once attackers have valid credentials, prevention efforts can drop sharply, as seen in a recent report measuring defenses technique by technique across 338 million simulations.
For individuals whose personal information may have been exposed in the breach, it’s essential to remain vigilant and monitor their credit reports closely. SickKids is offering complimentary credit monitoring and identity protection services for those affected, which can help mitigate potential risks.
Source: Bleeping Computer — 2026-08-21