Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2493+ Articles
160+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. SickKids Data Breach Exposes Employee and Job Applicant Info
SickKids Data Breach Exposes Employee and Job Applicant Info
NEWS

SickKids Data Breach Exposes Employee and Job Applicant Info

Toronto's SickKids hospital disclosed a breach affecting current and former employees and job applicants via a third-party software flaw. Patients unaffected.

Dylan H.

News Desk

August 21, 2026
4 min read

Toronto's Hospital for Sick Children (SickKids) has disclosed a cybersecurity incident that exposed the personal information of current and former employees, job applicants, and workers at affiliated organizations. The breach, discovered on July 9, 2026, was publicly disclosed on August 20, 2026 after an investigation confirmed unauthorized access to an HR and payroll system.

Patient clinical data was not affected. Patient care has continued normally throughout.


What Happened

An unauthorized party accessed a system supporting SickKids' external careers website and certain HR and payroll functions. The breach was caused by a vulnerability in a third-party software application used by SickKids and other unnamed organizations. The vendor has not been publicly identified.

SickKids engaged external cybersecurity experts immediately upon discovering the incident and temporarily took the careers website offline. The site has since been restored.


Who Is Affected

The breach affected individuals whose data was processed through the impacted system. SickKids has identified the primary exposure window as individuals employed between December 12, 2016 and August 31, 2018. In addition to SickKids staff, the breach also involves data related to:

  • Current and former employees
  • Job applicants who applied through the careers website
  • Workers at SickKids Foundation
  • Workers at Boomerang Health, a Vaughan-based pediatric clinic operated by the hospital

The exact number of affected individuals has not been disclosed — the investigation is ongoing and a final count is expected as the review continues.


What Data Was Exposed

SickKids described the impacted information as sensitive personal information consistent with HR and payroll system data. The hospital has not yet publicly itemized specific data field categories (such as Social Insurance Numbers, banking details, or home addresses), noting that outreach to confirmed individuals is underway and the investigation remains active.


SickKids' Response

The hospital has taken several steps since discovering the incident:

  • External cybersecurity experts were engaged immediately
  • The careers website was temporarily taken offline and has since been restored
  • Direct notification letters are being sent to individuals confirmed to be impacted
  • Out of an abundance of caution, broader notifications are going to all potentially affected individuals
  • 24 months of complimentary credit monitoring and identity protection services are being offered to those notified
  • The incident has been reported to relevant authorities

SickKids emphasized: "Clinical systems and patient information were not affected and patient care has continued as usual."


Third-Party Risk in Healthcare

This incident follows a familiar pattern in healthcare data breaches: an institution's own security posture is bypassed not through a direct attack, but through a vulnerability in a third-party vendor's software. The vendor in this case remains unnamed, but the breach affected SickKids and reportedly other organizations using the same application.

Healthcare institutions are prime targets due to the volume and sensitivity of data they process — not just patient records, but HR, payroll, and recruitment data that carry equally high personal risk when exposed. Third-party supply chain risk remains one of the most persistent blind spots in healthcare security programs.


What Affected Individuals Should Do

If you are or were employed at SickKids, SickKids Foundation, or Boomerang Health, or applied for a position through the careers website between December 2016 and August 2018, watch for notification letters from the hospital.

Steps to take:

  1. Enroll in the offered credit monitoring when notified — 24 months of coverage is being provided
  2. Place a fraud alert with Equifax and TransUnion Canada
  3. Monitor financial accounts for unusual activity
  4. Be alert for phishing — breached data is often used for targeted social engineering

Timeline

DateEvent
December 12, 2016Start of HR/payroll data exposure window
August 31, 2018End of primary exposure window
July 9, 2026Breach identified by SickKids
August 20, 2026Public disclosure and notification letters sent
August 21, 2026Investigation described as ongoing

Sources: CP24, CTV News, BleepingComputer. Investigation is ongoing and additional details are expected as SickKids completes its review.

#Data Breach#Healthcare#Canada#Third-Party Risk#HR Security#BleepingComputer

Related Articles

SickKids Hospital Hit by Cybercriminals Again as Employee Data Stolen

Canada's Hospital for Sick Children suffered a second cyber incident with employee data stolen via a compromised third-party app, four years after a 2022 ransomware attack.

4 min read

Amgen Cloud Breach Exposes Patient Health Data and Proprietary Research

Pharmaceutical giant Amgen disclosed a material data breach affecting cloud environments operated by third-party service providers, with threat actors exfiltrating patient protected health information and proprietary corporate data.

4 min read

Hims & Hers Warns of Data Breach After Zendesk Support

Telehealth giant Hims & Hers Health is warning customers of a data breach after support tickets were stolen from a third-party customer service platform,...

3 min read
Back to all News