SickKids Breached Again as Employee Data Stolen in Third-Party App
Canada's Hospital for Sick Children confirms a new cyberattack tied to a third-party app exposed current and former employee data, following its 2022 ransomware incident.

Executive Summary
Canada's Hospital for Sick Children (SickKids) disclosed a new cybersecurity incident that has exposed the personal information of current and former employees, as well as job applicants. The attack, which the hospital believes is linked to a third-party software application, briefly took down the institution's careers website. This marks the second significant cyberattack on the hospital in recent years, following a disruptive ransomware incident in December 2022.
While the breach did not compromise clinical systems or patient information, the theft of employee and applicant data poses significant identity theft and fraud risks. The hospital has begun notifying affected individuals and is offering two years of credit monitoring services. This incident underscores the persistent threat to healthcare organizations and the growing risk associated with third-party software supply chains.
Technical Analysis
The Hospital for Sick Children released a statement on Thursday, August 20, 2026, confirming the data theft incident. According to the statement, investigators believe the attack is tied to a third-party software application used by the hospital. The specific application has not been named, and the hospital did not respond to follow-up questions, instead resending the published statement.
The incident caused a brief outage of the hospital's careers website, which prompted the internal investigation. The notice does not specify the exact nature of the employee data that was taken, but the hospital stated that hackers likely stole information related to current and former employees, job applicants, and employees of related organizations, including the SickKids Foundation.
This attack follows a pattern of increasing third-party breaches in the healthcare sector. The hospital's 2022 ransomware attack, attributed to the LockBit gang, shut down systems ahead of the Christmas holiday and took weeks to recover from, impacting pharmacy systems, diagnostic imaging results, and internal timekeeping systems. In that instance, the attackers eventually apologized, provided a free decryptor, and claimed to have fired the affiliate responsible.
Mitigations & Recommendations
Given the confirmed data theft, affected individuals should take immediate steps to protect themselves against fraud and identity theft. The hospital is offering two years of credit monitoring, which should be enrolled in without delay.
Defenders and security teams in the healthcare sector should review their own third-party application inventories and access privileges. This incident highlights the critical need to monitor and audit integrations with external software vendors. Organizations should ensure that access to sensitive data, such as employee PII, is segmented and restricted, and that robust logging is in place to detect unauthorized access. For individuals, monitoring financial accounts and credit reports for suspicious activity is advised.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.
