SickKids breach exposes employee and applicant data
Affected individuals will be notified directly.

Image via Shutterstock
- SickKids reported a cybersecurity incident affecting employee, former employee, and job applicant data through third-party software.
- The hospital said patient information, clinical systems, and patient care were not affected by the breach.
- SickKids has not named the software vendor, disclosed affected data types, or said how many people were impacted.
- Potentially impacted people were offered 24 months of credit monitoring and identity protection as the investigation continues.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
SickKids, officially known as The Hospital for Sick Children, suffered a cybersecurity incident tied to a security flaw in a third-party software application that may have compromised the data of its current and former staff, as well as job applicants.
The hospital disclosed the incident on August 20th, saying that the intrusion temporarily affected the external Careers website as a result of a vulnerability in a third-party software application used by SickKids and other organizations. The website has since been restored.
The wording suggests that other companies using the same software could potentially be affected as part of a wider campaign, although neither the application nor its vendor was named.
Clinical systems and patient information were not affected, and patient care has continued as usual, SickKids said.
Following the incident, the hospital launched an investigation together with external cybersecurity experts and discovered that personal information of some current and former SickKids, Boomerang Health, a SickKids-owned pediatric clinic, and SickKids Foundation employees, as well as SickKids job applicants, may have been affected.
The review is currently ongoing.
SickKids did not disclose what categories of data were accessed and how many people appear to have been impacted. It’s also currently unclear when the intrusion took place.
Potentially impacted individuals have been alerted and offered 24 months of complimentary credit monitoring and identity protection services. The hospital said individuals confirmed to have been affected will be notified directly.
“Safeguarding the privacy and security of personal information is a responsibility SickKids takes seriously. We remain committed to maintaining strong protections and continuously enhancing our cybersecurity measures to help protect the information entrusted to us,” SickKids said.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Attacks on hospitals are controversial even within the cybercriminal community, and some hacking groups claim to avoid targeting critical infrastructure and healthcare facilities altogether.
In 2022, SickKids was hit by the LockBit ransomware group, which later publicly apologized for the attack and offered a free decryptor to restore the system.
However, in 2024, the same gang refused to reverse an attack on Saint Anthony Hospital in Chicago, which operates a dedicated children's hospital serving the city's West and Southwest Sides.