SickKids Data Breach Exposes Employee and Job Applicant Personal Data
SickKids data breach impacts employee and job applicant records
SickKids data breach impacts employee and job applicant records
The Hospital for SickChildren (SickKids) has confirmed a cybersecurity incident involving the exposure of personal data for current and former employees, as well as job applicants. The breach originated from a vulnerability in third-party software, according to the Toronto-based pediatric hospital. Clinical systems and patient records remained unaffected, though the public Careers website was temporarily taken offline. The hospital disclosed the incident after identifying unauthorized access to employee information.
Breach Origin and Scope
A media statement attributed the breach to a flaw in a third-party application used by SickKids and other organizations. While the statement did not specify the vendor, software name, or associated CVE identifier, it suggested the vulnerability may be part of a broader targeting effort. The external Careers site has since been restored, the statement noted. An investigation conducted with external cybersecurity experts revealed that data for employees of SickKids, Boomerang (a SickKids-owned pediatric clinic), and the SickKids Foundation, as well as job applicants, could have been compromised.
The hospital has not disclosed the specific data categories, affected numbers, or timeline of the breach. Affected individuals are being notified directly as the review continues. To mitigate risks, SickKids is providing 24 months of free credit monitoring and identity protection services.
Job Application Portals as Attack Targets
Job application portals are particularly attractive to attackers due to the sensitive information they collect, including full names, addresses, contact details, employment histories, and in some regions, government-issued identifiers. This data can facilitate identity fraud or social engineering attacks against hospital staff.
Previous Security Incidents
This marks the second major security incident involving SickKids in recent years. In December 2022, a ransomware attack disrupted internal systems, phone lines, and the hospital’s website, causing delays in lab and imaging services. The LockBit ransomware group later issued an apology for an affiliate’s breach of its policy against targeting medical institutions, providing a decryptor after the hospital spent nearly two weeks restoring systems independently.
Broader Healthcare Breach Context
In September 2023, SickKids was part of a larger breach affecting Ontario healthcare providers, linked to the exploitation of a zero-day vulnerability in MOVEit Transfer (CVE-2023-34362). The incident exposed data for 3.4 million individuals, including names, addresses, birth dates, and health card numbers. Healthcare organizations remain prime targets for cybercriminals, with pediatric hospitals holding decades of sensitive records. Attackers often exploit stolen credentials, with 37% of malicious activities going undetected despite existing defenses.
Related Data Breaches
- Sakura Internet hack impacts 1.36 million accounts
- Healthtech firm CareCloud breach affects 3.7 million patients
- Accenture confirms data breach after hacker offers stolen information for sale
- Pokémon Center data breach exposes customer details, leads to order cancellations
- French tax authority breach impacts 678,000 individuals
- Canada Cyber Incident Data Breach
Ax Sharma
Ax Sharma is a security researcher and journalist specializing in malware analysis and cybercrime investigations. His work focuses on open-source software security, threat intelligence, and reverse engineering. He contributes to outlets such as BBC, Channel 5 (UK), Fortune, and WIRED, and is an active member of the OWASP Foundation and the Canadian Association of Journalists.
