The Hospital for Sick Children (SickKids) in Toronto, Canada, has disclosed a new cyber incident in which employee data was stolen by threat actors exploiting a third-party software application. The hospital, one of the largest pediatric academic medical centres in the world, issued a statement warning staff of the breach on Thursday.
This is the second significant cyber incident to strike SickKids in recent years. In December 2022, the hospital was hit by a ransomware attack that disrupted several internal systems and delayed diagnostic results for patients during the holiday season.
What Happened
According to SickKids, the new incident is a data theft event tied to a third-party software application used by the hospital. Cybercriminals compromised the application — or an account within it — and exfiltrated employee data. The hospital has not yet disclosed the name of the vendor, the specific data types involved, or the estimated number of affected employees.
The hospital stated it is investigating the scope of the exposure and will notify affected individuals as more information becomes available. Law enforcement has been engaged.
A Pattern of Healthcare Targeting
SickKids' repeat victimization reflects a broader, troubling trend: healthcare organizations are among the most frequently targeted sectors in cybercrime, and children's hospitals are not exempt from attacks. Threat actors view hospitals as high-pressure environments where a rapid ransom payment or compliance is more likely — and where the reputational cost of disruption is significant.
The 2022 ransomware attack on SickKids was attributed to a LockBit affiliate, though LockBit's operators subsequently issued an unusual public apology and provided a decryptor free of charge — an admission that the targeting of a pediatric hospital crossed an implicit line even among ransomware operators. This latest incident carries a different profile (data theft rather than operational disruption), but the targeting of the same institution twice underscores persistent threat actor interest in healthcare environments.
Third-Party Risk in Healthcare
Like the U.S. Bank fourth-party exposure reported the same day, the SickKids breach traces to a third-party application rather than a direct compromise of the hospital's core systems. Healthcare organizations increasingly depend on specialized software vendors for clinical, HR, and administrative functions — and each vendor relationship is a potential attack surface.
For healthcare security teams, the incident reinforces several key risk management imperatives:
- Inventory all third-party applications that handle employee or patient data
- Include breach notification requirements in vendor contracts with clear timelines
- Evaluate vendor security posture as part of procurement — particularly for applications handling sensitive personnel data
- Limit data minimization at the vendor level — vendors should only hold the data they need for their specific function
- Monitor dark web and threat intelligence sources for hospital-related data appearing in breach markets
What Affected Employees Should Do
SickKids employees who may be affected by this incident should:
- Watch for phishing emails that reference their employment at SickKids, as stolen employee data is commonly used to craft convincing lures
- Review benefit and payroll accounts for any unauthorized changes or access
- Change passwords for any accounts that may share credentials with systems or applications accessed through work
- Monitor credit files if Social Insurance Numbers or financial data may have been involved
- Await official notification from SickKids HR or security teams with specific guidance on what data was exposed
Broader Implications
Back-to-back cyber incidents at the same healthcare institution — separated by roughly three and a half years — raise questions about whether sufficient security improvements were made following the 2022 ransomware attack. Healthcare boards and executive teams are increasingly being held accountable not just for initial incident response, but for the durability of post-incident remediation.
Canadian regulators including the Office of the Privacy Commissioner have signaled closer scrutiny of healthcare organizations' data protection obligations under PIPEDA. If patient data is ultimately determined to have been affected — even indirectly through employee records — additional regulatory and public disclosure obligations would apply.