The Hospital for Sick Children in Toronto has disclosed that a cybersecurity incident exposed the personal information of some current and former employees and job applicants. The breach stemmed from a vulnerability in third-party software, according to the hospital鈥檚 media statement. SickKids said the issue affected its public-facing Careers website, which was temporarily taken offline but has since been safely restored. Clinical systems and patient records were not touched, and patient care continued as usual throughout the incident.

The hospital said it launched an investigation with outside cybersecurity experts after learning of the intrusion. Their findings indicate that personal information belonging to current and former employees of SickKids, Boomerang, a SickKids-owned pediatric clinic, and the SickKids Foundation may have been exposed, along with data from SickKids job applicants. SickKids has not named the third-party vendor, the specific application, or the vulnerability involved, nor has it said what categories of data were compromised or how many people are affected. The hospital鈥檚 review of the impacted information is ongoing, with individuals confirmed as affected to be notified directly.

Out of an abundance of caution, SickKids says it has alerted everyone potentially caught up in the incident and is offering 24 months of complimentary credit monitoring and identity protection. The hospital has not disclosed when the intrusion took place. Job application portals are a particularly attractive target for data thieves because applicants routinely provide full names, home addresses, phone numbers, employment histories, and, in some jurisdictions, government identifiers. That data is useful for identity fraud and for building convincing social engineering pretexts against hospital staff.

This is not the first security incident to hit SickKids in recent years. In December 2022, the hospital was struck by a ransomware attack that disrupted internal systems, phone lines, and its website, and caused delays in lab and imaging results. In September 2023, SickKids was among Ontario healthcare providers affected by a breach at a third-party organization it shares perinatal and child health data with. That incident stemmed from mass exploitation of the MOVEit Transfer zero-day vulnerability and exposed information on 3.4 million people, including names, home addresses, dates of birth, and health card numbers.

Healthcare remains one of the most heavily targeted sectors for both ransomware crews and data extortion groups, and pediatric hospitals in particular hold decades of sensitive records. The Blue Report 2026, which measures defenses across 338 million simulations in customer production environments, notes that once attackers use valid credentials, prevention effectiveness drops sharply. For US technology readers, this incident underscores a broader risk: third-party software flaws affecting job application systems can expose sensitive personal data across borders, and hospitals in Canada often share threat intelligence and vendor ecosystems with US institutions. SickKids has not yet provided further details on the timeline or scope of the breach, and the hospital says it is notifying affected individuals directly as its review continues.

More cybersecurity news from TechManNews.