Toronto’s Hospital for Sick Children says a cybersecurity incident exposed personal information belonging to some current and former employees, job applicants, SickKids Foundation staff, and staff at its Boomerang clinic. SickKids says the intrusion came through a vulnerability in unnamed third-party software used by multiple organizations; the public Careers site was temporarily taken offline and restored, while clinical systems and patient records were not affected. The hospital has not yet named the vendor, product, CVE, attack date, or total number affected.
Why it matters: This affects workers and applicants whose identity and employment data could be used for fraud or convincing follow-on phishing. Potentially affected people should watch for direct notice, use the offered credit monitoring, and be extra cautious about messages referencing job applications or HR matters.
2026.08.21
97% relevant
This article appears to cover the same SickKids incident and adds that the breach was tied to a third-party software application, likely involved theft of current and former employee, applicant, and related-organization data including the SickKids Foundation, briefly took down the careers website, and did not affect clinical systems or patient information.
Ax Sharma
2026.08.21
100% relevant
This article establishes a distinct new breach event at SickKids tied to a vulnerable third-party application, not the 2022 ransomware incident or the earlier MOVEit-related third-party breach.
← Back to all stories