HackMyIP
← Back to News
2026-08-21 The Record

SickKids Hospital Breached Again: Employee Data Stolen via Third-Party App

Data BreachPrivacySupply Chain

Canada's largest pediatric health center, the Hospital for Sick Children (SickKids), has disclosed a second major cybersecurity incident in three years, with attackers stealing personal information belonging to current and former employees, job applicants, and staff at affiliated organizations including the SickKids Foundation. The Toronto-based hospital announced the breach on Thursday, attributing the intrusion to a compromise of a third-party software application rather than a direct attack on its own network. The incident briefly knocked the hospital's careers website offline and triggered a full investigation, though SickKids confirmed that no clinical systems or patient health records were accessed. The specific nature of the stolen employee data has not been disclosed, but affected individuals have been notified and offered two years of complimentary credit monitoring services. Employees concerned about exposure can verify their credentials using an email breach checker and reinforce account security with a password checker to identify weak or compromised credentials.

This latest breach echoes a far more disruptive ransomware attack that struck SickKids in December 2022, just before the Christmas holiday. That incident disabled pharmacy systems, diagnostic imaging results, and internal staff timekeeping infrastructure, and it took weeks for the hospital to fully restore operations. The threat actors responsible eventually issued a public apology, released a free decryptor, and claimed to have terminated the affiliate who carried out the attack. The recurrence of an incident at the same institution underscores the persistent risk facing healthcare organizations, particularly those with sprawling third-party vendor ecosystems that expand the attack surface well beyond core clinical infrastructure.

SickKids is far from alone. Within the same week, two other major healthcare organizations reported significant breaches. Baylor Genetics disclosed that a June incident exposed medical testing information, laboratory results, health insurance details, and Social Security numbers, while CareCloud, an electronic health records vendor, confirmed that a March cybersecurity incident impacted approximately 3.7 million individuals. The clustering of these disclosures highlights how threat actors continue to view the healthcare sector as a high-value target, given the sensitivity of the data held and the operational pressure that downtime creates. Professionals working in or with healthcare IT should run a comprehensive privacy checkup to assess exposure across accounts and devices tied to organizational systems.

Healthcare sector breaches of this scale typically create downstream risks that extend well beyond the immediate victim organization, as stolen employee data is often recycled in credential-stuffing campaigns, phishing lures, and identity fraud schemes. For affected staff and applicants, the recommended steps include monitoring financial accounts, enabling multi-factor authentication on all professional and personal logins, and remaining alert to unsolicited communications referencing the hospital or related entities.

Source: The Record →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →