Hospital for Sick Children (SickKids) Data Breach Exposes Employee Information via Third-Party Software Vulnerability
Hospital for Sick Children (SickKids) Data Breach Exposes (TL-2026-2106) is a medium-severity data breach, first published 2026-08-21. It has no confirmed attribution, affects Undisclosed third-party software vendor Third-party HR/careers/payroll, maps to 10 MITRE ATT&CK techniques (T1071.001, T1190, T1199), and is covered by 9 detection rules and 8 indicators of compromise.
Key facts for TL-2026-2106
- Threat ID
- TL-2026-2106
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- 2026-08-21
- Last reviewed
- 2026-08-21
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- health
- Target regions
- canada, North America
- Detection rules
- 9
- Indicators of compromise
- 8
Malware and tooling in Hospital for Sick Children (SickKids) Data Breach Exposes
Malware and tooling: LEMURLOOT
SickKids (The Hospital for Sick Children, Toronto) disclosed that unauthorized actors accessed a third-party system supporting its careers website and Human Resources/payroll functions, exposing personal information of current and former employees, job applicants, and staff of the SickKids Foundation and Boomerang Health. No clinical systems or patient data were affected; SickKids is offering 24 months of credit monitoring.
How Hospital for Sick Children (SickKids) Data Breach Exposes works
The Hospital for Sick Children (SickKids), a pediatric hospital and research institute in Toronto, Ontario, disclosed on August 20-21, 2026 that it had identified unauthorized access to a system supporting both its external Careers website and certain Human Resources functions, including payroll. SickKids states the intrusion was first identified on July 9, 2026, and attributes root cause to a vulnerability in a third-party software application that is also used by other, unnamed organizations -- no vendor name or CVE identifier has been publicly disclosed for this vulnerability.
Investigators believe attackers accessed and likely stole personal information belonging to current and former SickKids employees, job applicants whose data was held in the Careers system, and staff of two related organizations that share the same third-party platform: the SickKids Foundation and Boomerang Health (a SickKids-owned pediatric clinic in Vaughan, Ontario). SickKids specifically warned that individuals who were part of its workforce between December 12, 2016 and August 31, 2018 may have had sensitive personal information exposed on the impacted system. The hospital has not disclosed the exact categories of data taken, the total number of individuals affected, or the specific technical vulnerability exploited, saying its review remains ongoing with the assistance of external cybersecurity experts. The external-facing Careers website was briefly taken offline during the investigation and has since been restored. SickKids confirmed that clinical systems and patient/personal health information were not accessed or affected. Affected individuals are being notified directly and offered 24 months of complimentary credit monitoring and identity-theft protection.
No threat-actor group has claimed responsibility or been named in connection with this incident, and there is no public evidence of extortion, ransomware, or a leak-site posting tied to it as of this writing.
This is the third publicly reported cybersecurity incident affecting SickKids in roughly four years, establishing a recurring pattern of third-party/supply-chain exposure at this hospital rather than a single isolated event. In December 2022, an affiliate of the LockBit ransomware-as-a-service group encrypted SickKids systems, disrupting lab results, diagnostic imaging, phone lines, and payroll systems for weeks; SickKids did not pay a ransom, and LockBit's core operators later issued a rare public apology, stating the affiliate had violated the group's rule against encrypting medical institutions, expelled the affiliate, and provided a free decryptor roughly two weeks after the attack. In September 2023, SickKids was one of many Ontario healthcare providers swept up in a breach at BORN Ontario, the provincial perinatal and child-health data registry with which SickKids shares pregnancy/birth/newborn-care data -- that incident stemmed from mass exploitation of the Progress MOVEit Transfer SQL-injection zero-day (CVE-2023-34362, CVSS 9.8) and exposed personal and health information on roughly 3.4 million people across Ontario. Together with the current incident, these three events show SickKids being repeatedly affected through pathways outside its direct control: a ransomware affiliate, a shared government-adjacent data-sharing partner, and now a shared third-party HR/careers software vendor -- a pattern consistent with the broader healthcare-sector trend of attackers achieving mass impact by targeting widely-used third-party software/platforms rather than individual hospital networks directly (the same mass-exploitation dynamic seen with MOVEit/Cl0p in 2023).
MITRE ATT&CK techniques used in TL-2026-2106
Command and Control
Initial Access
T1190 Exploit Public-Facing Application; T1199 Trusted Relationship
Collection
T1213 Data from Information Repositories; T1530 Data from Cloud Storage
Impact
Persistence
Exfiltration
T1567 Exfiltration Over Web Service
Reconnaissance
Affected products and versions in Hospital for Sick Children (SickKids) Data Breach Exposes
- Undisclosed third-party software vendor — Third-party HR/careers/payroll application (also used by other, unnamed organizations)
Vulnerable versions: Unknown - not publicly disclosed
Fixed in: Unknown - not publicly disclosed
Remediation for Hospital for Sick Children (SickKids) Data Breach Exposes
Patches
- Apply the affected third-party software vendor's security patch once publicly disclosed (vendor and CVE not yet named)
Immediate actions
- Engage external cybersecurity experts to scope the intrusion into the shared third-party careers/HR/payroll system and confirm the exploited vulnerability is remediated
- Notify and offer 24 months of complimentary credit monitoring and identity-theft protection to all current/former employees, job applicants, and affiliated-org staff (SickKids Foundation, Boomerang Health) potentially in the impacted system, with particular attention to the December 12, 2016 - August 31, 2018 workforce window
- Rotate credentials and review access/audit logs for the affected third-party application for signs of continued or repeated unauthorized access
Workarounds
- Restrict, closely monitor, or take offline external access to the affected careers/HR/payroll portal until the vulnerability is confirmed remediated
Longer-term hardening
- Conduct third-party/vendor risk assessments for all SaaS platforms handling employee PII (HR, payroll, applicant tracking systems), including contractual security requirements and periodic independent penetration testing
- Segment HR, payroll, and recruiting systems from other business-critical infrastructure so a single vendor compromise cannot cascade further
- Establish a formal third-party incident-notification SLA with software vendors given the hospital's recurring exposure through shared/partner platforms (BORN Ontario 2023, this vendor in 2026)
Timeline of Hospital for Sick Children (SickKids) Data Breach Exposes
- A LockBit ransomware-as-a-service affiliate attacks SickKids, disrupting lab results, diagnostic imaging, phone lines, and payroll systems for weeks; SickKids does not pay a ransom.
- LockBit's core operators publicly apologize for the SickKids attack, state the responsible affiliate violated the group's rule against encrypting medical institutions, expel the affiliate, and release a free decryptor.
- SickKids discloses it is among many Ontario healthcare providers affected by a breach at BORN Ontario, the province's perinatal/child health registry, stemming from mass exploitation of the Progress MOVEit Transfer zero-day (CVE-2023-34362); roughly 3.4 million people's data is exposed province-wide.
- SickKids first identifies unauthorized access to a system supporting its external Careers website and certain Human Resources functions, including payroll, later attributed to a vulnerability in third-party software also used by other organizations.
- SickKids publicly discloses the incident, stating personal information of current/former employees, job applicants, and staff of the SickKids Foundation and Boomerang Health may have been accessed; the external Careers website was briefly taken offline and has since been restored.
- The Record, BleepingComputer, SC Media, and other outlets report the breach; SickKids confirms clinical systems and patient information were not affected and offers 24 months of complimentary credit monitoring and identity-theft protection to impacted individuals.
Sources cited for Hospital for Sick Children (SickKids) Data Breach Exposes
- Canada's Hospital for Sick Children attacked by cybercriminals again as employee data stolen
- SickKids data breach exposes employee and job applicant info
- Hospital for Sick Children discloses employee data breach due to third-party software flaw
- SickKids responding to cybersecurity 'incident' which compromised some employee info
- SickKids data breach exposes cybersecurity risk for employee information
- SickKids hit by cyber breach targeting employee info
- SickKids children's hospital bandages up careers website after intruder breaks in
- SickKids hit by ransomware attack affecting some phone lines, web pages
- Ransomware group LockBit apologizes saying 'partner' was behind SickKids attack
- SickKids impacted by BORN Ontario data breach that hit 3.4 million
- CVE-2023-34362 Detail (Progress MOVEit Transfer SQL Injection)
- #StopRansomware: CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit Vulnerability (AA23-158A)
More in data breach
- ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS File Upload Flaw, Threatens 72-Hour Extortion
- Gyazo Data Breach: Helpfeel Discloses 23.62M User Records and ~492M Image Metadata Records Exposed via Image Upload Server Exploit
- Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)
- Revolut Discloses Data Breach via Government-Impersonation Social Engineering, Exposing Customer Financial and Passport Data
- TELUS Warns Customers of 16-Month Account Takeover Breach via Compromised Credentials
Detection coverage for TL-2026-2106
As of 2026-08-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2106 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.