The Hospital for Sick Children (SickKids) in Toronto disclosed a cybersecurity incident in which attackers gained unauthorized access through a vulnerability in an unnamed third-party software application, exposing personal information tied to current and former employees, job applicants, and staff associated with the SickKids Foundation and Boomerang. The intrusion briefly forced the hospital to take its public-facing careers website offline before restoring it, and investigators believe data was stolen during the breach.
SickKids said its clinical systems, patient records, and patient care operations were not affected. The hospital is investigating with external cybersecurity experts, has begun notifying potentially affected individuals, and is offering 24 months of credit monitoring and identity protection. The organization has not yet identified the software vendor, disclosed a CVE, or provided the full scope and timing of the compromise.

See attribution, scope, and your downstream exposure.
8 events from the most recent confirmed update back to the earliest known activity.
A letter viewed by CTV News said SickKids first identified the cybersecurity incident on July 9. The affected system supported the hospital’s careers website and certain human resources functions, including payroll.
In September 2023, SickKids was among Ontario healthcare providers affected by a third-party breach tied to mass exploitation of MOVEit Transfer vulnerability CVE-2023-34362. The breach reportedly exposed data on 3.4 million people, including names, addresses, dates of birth, and health card numbers.
In December 2022, SickKids suffered a ransomware attack that disrupted internal systems, hospital phone lines, and its website. The incident also affected operations including pharmacy systems, diagnostic imaging or lab results, and staff timekeeping.
After identifying the employee and applicant data security incident, SickKids said it notified relevant law enforcement authorities. The hospital also said clinical systems and patient data were unaffected and patient care continued without disruption.
SickKids said it alerted everyone potentially affected out of caution and will directly notify individuals confirmed as impacted. The hospital is offering 24 months of complimentary credit monitoring and identity protection services.
Following the incident, SickKids temporarily took its public-facing Careers website offline and launched an investigation with outside cybersecurity experts. The hospital later restored the site safely.
SickKids disclosed a recent cybersecurity incident involving unauthorized access and likely theft of personal information linked to a third-party software application. The potentially affected groups include current and former employees, job applicants, employees of Boomerang, and employees of the SickKids Foundation.
After the 2022 ransomware attack, the LockBit gang publicly apologized and offered SickKids a free decryptor. One report also says the group claimed it fired the affiliate responsible for targeting the hospital.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
7 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcecyberveille.ch
Open sourcescworld.com
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourcectvnews.ca
Open sourcesickkids.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.