Hospital for Sick Children (SickKids) Data Breach Exposes Employee Information via Third-Party Software Vulnerability

Hospital for Sick Children (SickKids) Data Breach Exposes (TL-2026-2106) is a medium-severity data breach, first published 2026-08-21. It has no confirmed attribution, affects Undisclosed third-party software vendor Third-party HR/careers/payroll, maps to 10 MITRE ATT&CK techniques (T1071.001, T1190, T1199), and is covered by 9 detection rules and 8 indicators of compromise.

Key facts for TL-2026-2106

Threat ID
TL-2026-2106
Severity
MEDIUM
Status
ACTIVE
Category
DATA_BREACH
First published
2026-08-21
Last reviewed
2026-08-21
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
health
Target regions
canada, North America
Detection rules
9
Indicators of compromise
8

Malware and tooling in Hospital for Sick Children (SickKids) Data Breach Exposes

Malware and tooling: LEMURLOOT

SickKids (The Hospital for Sick Children, Toronto) disclosed that unauthorized actors accessed a third-party system supporting its careers website and Human Resources/payroll functions, exposing personal information of current and former employees, job applicants, and staff of the SickKids Foundation and Boomerang Health. No clinical systems or patient data were affected; SickKids is offering 24 months of credit monitoring.

How Hospital for Sick Children (SickKids) Data Breach Exposes works

The Hospital for Sick Children (SickKids), a pediatric hospital and research institute in Toronto, Ontario, disclosed on August 20-21, 2026 that it had identified unauthorized access to a system supporting both its external Careers website and certain Human Resources functions, including payroll. SickKids states the intrusion was first identified on July 9, 2026, and attributes root cause to a vulnerability in a third-party software application that is also used by other, unnamed organizations -- no vendor name or CVE identifier has been publicly disclosed for this vulnerability.

Investigators believe attackers accessed and likely stole personal information belonging to current and former SickKids employees, job applicants whose data was held in the Careers system, and staff of two related organizations that share the same third-party platform: the SickKids Foundation and Boomerang Health (a SickKids-owned pediatric clinic in Vaughan, Ontario). SickKids specifically warned that individuals who were part of its workforce between December 12, 2016 and August 31, 2018 may have had sensitive personal information exposed on the impacted system. The hospital has not disclosed the exact categories of data taken, the total number of individuals affected, or the specific technical vulnerability exploited, saying its review remains ongoing with the assistance of external cybersecurity experts. The external-facing Careers website was briefly taken offline during the investigation and has since been restored. SickKids confirmed that clinical systems and patient/personal health information were not accessed or affected. Affected individuals are being notified directly and offered 24 months of complimentary credit monitoring and identity-theft protection.

No threat-actor group has claimed responsibility or been named in connection with this incident, and there is no public evidence of extortion, ransomware, or a leak-site posting tied to it as of this writing.

This is the third publicly reported cybersecurity incident affecting SickKids in roughly four years, establishing a recurring pattern of third-party/supply-chain exposure at this hospital rather than a single isolated event. In December 2022, an affiliate of the LockBit ransomware-as-a-service group encrypted SickKids systems, disrupting lab results, diagnostic imaging, phone lines, and payroll systems for weeks; SickKids did not pay a ransom, and LockBit's core operators later issued a rare public apology, stating the affiliate had violated the group's rule against encrypting medical institutions, expelled the affiliate, and provided a free decryptor roughly two weeks after the attack. In September 2023, SickKids was one of many Ontario healthcare providers swept up in a breach at BORN Ontario, the provincial perinatal and child-health data registry with which SickKids shares pregnancy/birth/newborn-care data -- that incident stemmed from mass exploitation of the Progress MOVEit Transfer SQL-injection zero-day (CVE-2023-34362, CVSS 9.8) and exposed personal and health information on roughly 3.4 million people across Ontario. Together with the current incident, these three events show SickKids being repeatedly affected through pathways outside its direct control: a ransomware affiliate, a shared government-adjacent data-sharing partner, and now a shared third-party HR/careers software vendor -- a pattern consistent with the broader healthcare-sector trend of attackers achieving mass impact by targeting widely-used third-party software/platforms rather than individual hospital networks directly (the same mass-exploitation dynamic seen with MOVEit/Cl0p in 2023).

MITRE ATT&CK techniques used in TL-2026-2106

Command and Control

T1071.001 Web Protocols

Initial Access

T1190 Exploit Public-Facing Application; T1199 Trusted Relationship

Collection

T1213 Data from Information Repositories; T1530 Data from Cloud Storage

Impact

T1489 Service Stop

Persistence

T1505.003 Web Shell

Exfiltration

T1567 Exfiltration Over Web Service

Reconnaissance

T1591 Gather Victim Org Information; T1595 Active Scanning

Affected products and versions in Hospital for Sick Children (SickKids) Data Breach Exposes

  • Undisclosed third-party software vendor — Third-party HR/careers/payroll application (also used by other, unnamed organizations)
    Vulnerable versions: Unknown - not publicly disclosed
    Fixed in: Unknown - not publicly disclosed

Remediation for Hospital for Sick Children (SickKids) Data Breach Exposes

Patches

  • Apply the affected third-party software vendor's security patch once publicly disclosed (vendor and CVE not yet named)

Immediate actions

  • Engage external cybersecurity experts to scope the intrusion into the shared third-party careers/HR/payroll system and confirm the exploited vulnerability is remediated
  • Notify and offer 24 months of complimentary credit monitoring and identity-theft protection to all current/former employees, job applicants, and affiliated-org staff (SickKids Foundation, Boomerang Health) potentially in the impacted system, with particular attention to the December 12, 2016 - August 31, 2018 workforce window
  • Rotate credentials and review access/audit logs for the affected third-party application for signs of continued or repeated unauthorized access

Workarounds

  • Restrict, closely monitor, or take offline external access to the affected careers/HR/payroll portal until the vulnerability is confirmed remediated

Longer-term hardening

  • Conduct third-party/vendor risk assessments for all SaaS platforms handling employee PII (HR, payroll, applicant tracking systems), including contractual security requirements and periodic independent penetration testing
  • Segment HR, payroll, and recruiting systems from other business-critical infrastructure so a single vendor compromise cannot cascade further
  • Establish a formal third-party incident-notification SLA with software vendors given the hospital's recurring exposure through shared/partner platforms (BORN Ontario 2023, this vendor in 2026)

Timeline of Hospital for Sick Children (SickKids) Data Breach Exposes

  • A LockBit ransomware-as-a-service affiliate attacks SickKids, disrupting lab results, diagnostic imaging, phone lines, and payroll systems for weeks; SickKids does not pay a ransom.
  • LockBit's core operators publicly apologize for the SickKids attack, state the responsible affiliate violated the group's rule against encrypting medical institutions, expel the affiliate, and release a free decryptor.
  • SickKids discloses it is among many Ontario healthcare providers affected by a breach at BORN Ontario, the province's perinatal/child health registry, stemming from mass exploitation of the Progress MOVEit Transfer zero-day (CVE-2023-34362); roughly 3.4 million people's data is exposed province-wide.
  • SickKids first identifies unauthorized access to a system supporting its external Careers website and certain Human Resources functions, including payroll, later attributed to a vulnerability in third-party software also used by other organizations.
  • SickKids publicly discloses the incident, stating personal information of current/former employees, job applicants, and staff of the SickKids Foundation and Boomerang Health may have been accessed; the external Careers website was briefly taken offline and has since been restored.
  • The Record, BleepingComputer, SC Media, and other outlets report the breach; SickKids confirms clinical systems and patient information were not affected and offers 24 months of complimentary credit monitoring and identity-theft protection to impacted individuals.

Sources cited for Hospital for Sick Children (SickKids) Data Breach Exposes

More in data breach

Detection coverage for TL-2026-2106

As of 2026-08-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2106 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats