Hospital for Sick Children (SickKids) Data Breach Exposes Employee Information via Third-Party Software Vulnerability — Threadlinqs Intelligence
As of 2026-08-21, Hospital for Sick Children (SickKids) Data Breach Exposes Employee Information via Third-Party Software Vulnerability is a medium-severity data breach threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 8 indicators of compromise.
Threat ID: TL-2026-2106 · Severity: MEDIUM · Status: ACTIVE · Category: DATA_BREACH
SickKids (The Hospital for Sick Children, Toronto) disclosed that unauthorized actors accessed a third-party system supporting its careers website and Human Resources/payroll functions, exposing
The Hospital for Sick Children (SickKids), a pediatric hospital and research institute in Toronto, Ontario, disclosed on August 20-21, 2026 that it had identified unauthorized access to a system supporting both its external Careers website and certain Human Resources functions, including payroll. SickKids states the intrusion was first identified on July 9, 2026, and attributes root cause to a vulnerability in a third-party software application that is also used by other, unnamed organizations -- no vendor name or CVE identifier has been publicly disclosed for this vulnerability.
Investigators believe attackers accessed and likely stole personal information belonging to current and former SickKids employees, job applicants whose data was held in the Careers system, and staff of two related organizations that share the same third-party platform: the SickKids Foundation and Boomerang Health (a SickKids-owned pediatric clinic in Vaughan, Ontario). SickKids specifically warned that individuals who were part of its workforce between December 12, 2016 and August 31, 2018 may have had sensitive personal information exposed on the impacted system. The hospital has not disclosed the exact categories of data taken, the total number of individuals affected, or the specific technical vulnerability exploited, saying its review remains ongoing with the assistance of external cybersecurity experts. The external-facing Careers website was briefly taken offline during the investigation and has since been restored. SickKids confirmed that clinical systems and patient/personal health information were not accessed or affected. Affected individuals are being notified directly and offered 24 months of complimentary credit monitoring and identity-theft protection.
No threat-actor group has claimed responsibility or been named in connection with this incident, and there is no public evidence of extortion, ransomware, or a leak-site posting tied to it as of this writing.
This is the third publicly reported cybersecurity incident affecting SickKids in roughly four years, establishing a recurring pattern of third-party/supply-chain exposure at this hospital rather than a single isolated event. In December 2022, an affiliate of the LockBit ransomware-as-a-service group encrypted SickKids systems, disrupting lab results, diagnostic imaging, phone lines, and payroll systems for weeks; SickKids did not pay a ransom, and LockBit's core operators later issued a rare public apology, stating the affiliate had violated the group's rule against encrypting medical institutions, expelled the affiliate, and provided a free decryptor roughly two weeks after the attack. In September 2023, SickKids was one of many Ontario healthcare providers swept up in a breach at BORN Ontario, the provincial perinatal and child-health data registry with which SickKids shares pregnancy/birth/newborn-care data -- that incident stemmed from mass exploitation of the Progress MOVEit Transfer SQL-injection zero-day (CVE-2023-34362, CVSS 9.8) and exposed personal and health information on roughly 3.4 million people across Ontario. Together with the current incident, these three events show SickKids being repeatedly affected through pathways outside its direct control: a ransomware affiliate, a shared government-adjacent data-sharing partner, and now a shared third-party HR/careers software vendor -- a pattern consistent with the broader healthcare-sector trend of attackers achieving mass impact by targeting widely-used third-party software/platforms rather than individual hospital networks directly (the same mass-exploitation dynamic seen with MOVEit/Cl0p in 2023).
Target sectors: health
Target regions: canada, North America
Timeline
- A LockBit ransomware-as-a-service affiliate attacks SickKids, disrupting lab results, diagnostic imaging, phone lines, and payroll systems for weeks; SickKids does not pay a ransom.
- LockBit's core operators publicly apologize for the SickKids attack, state the responsible affiliate violated the group's rule against encrypting medical institutions, expel the affiliate, and release a free decryptor.
- SickKids discloses it is among many Ontario healthcare providers affected by a breach at BORN Ontario, the province's perinatal/child health registry, stemming from mass exploitation of the Progress MOVEit Transfer zero-day (CVE-2023-34362); roughly 3.4 million people's data is exposed province-wide.
- SickKids first identifies unauthorized access to a system supporting its external Careers website and certain Human Resources functions, including payroll, later attributed to a vulnerability in third-party software also used by other organizations.
- SickKids publicly discloses the incident, stating personal information of current/former employees, job applicants, and staff of the SickKids Foundation and Boomerang Health may have been accessed; the external Careers website was briefly taken offline and has since been restored.
- The Record, BleepingComputer, SC Media, and other outlets report the breach; SickKids confirms clinical systems and patient information were not affected and offers 24 months of complimentary credit monitoring and identity-theft protection to impacted individuals.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 8 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
DATA_BREACH, MEDIUM, threat intelligence, cybersecurity, T1595, T1591, T1190, T1199, T1213, T1530, T1567, T1505.003, T1071.001, T1489