Published · 2d agoSecurity3 min read
SickKids blames a third-party app for its breach, then declines to name it
The Toronto hospital says the flaw sits in software used by other organizations too. It has not said which software, which leaves those organizations nothing to act on.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- SickKids disclosed that the personal information of some current and former employees, as well as job applicants, was exposed in a cybersecurity incident, and says the breach stemmed from a flaw in third-party software.
- The hospital attributes the breach to a vulnerability in a third-party software application that it says is used by SickKids and other organizations, according to a media statement.
- The hospital has not named the vendor, the application, or the CVE involved.
- BleepingComputer writes that the hospital's framing appears to suggest there is a wider campaign against users of the same product.
- The external Careers website was temporarily affected and has since been safely restored, per the hospital's statement; it was temporarily pulled offline.
Compiled by The WatchSomething wrong?How this is made
Why it matters
The Hospital for Sick Children in Toronto has told current and former staff and job applicants that their personal information may have been exposed in a cybersecurity incident, and attributes it to a vulnerability in a third-party software application that it says is used by SickKids and other organizations [1][3]. It has not named the vendor, the application, or the CVE [4], which means the other organizations it gestures at have been handed a warning with nothing in it they can act on.
BleepingComputer reads that framing as suggesting a wider campaign against users of the same product [5]. If that is right, the disclosure is worse than incomplete, it is inverted: the hospital has published the part that helps nobody and withheld the part that would let a peer institution check a version number and close a hole. If it is not right, the phrase "and other organizations" is doing reputational work rather than informational work.
What SickKids has confirmed is narrow. The external Careers website was temporarily affected and has since been safely restored [6]. Clinical systems and patient information were not affected, and patient care continued as usual, according to the hospital [7]. It opened an investigation with outside cybersecurity experts [8], and the findings so far indicate that personal information belonging to current and former SickKids, Boomerang and SickKids Foundation employees, as well as SickKids job applicants, may have been exposed [9].
What it has not said is most of the rest: which categories of data were involved, how many people are affected, or when the intrusion happened [10]. The review of impacted information is ongoing, and people confirmed as affected will be notified directly [11]. In the meantime the hospital says it has alerted everyone potentially caught up in the incident out of an abundance of caution, and is offering 24 months of credit monitoring and identity protection [12].
Recruiting portals are worth this attention because of what applicants volunteer: full names, home addresses, phone numbers, employment histories, and in some jurisdictions government identifiers, all useful for identity fraud and for building credible pretexts against hospital staff [13]. A stolen applicant list is a phishing target list with the employer relationship pre-established.
The pattern here is the more useful signal. In December 2022 SickKids was hit by ransomware that disrupted internal systems, phone lines and its website and delayed lab and imaging results [14]; LockBit later apologised publicly, said the affiliate had broken its rules against encrypting medical institutions, and provided a free decryptor, but only after the hospital had spent nearly two weeks restoring systems itself [15]. In September 2023 the hospital was among Ontario healthcare providers caught in a breach at a third-party organization it shares perinatal and child health data with, via mass exploitation of the MOVEit Transfer zero-day CVE-2023-34362, exposing data on 3.4 million people including names, addresses, dates of birth and health card numbers [16]. Two of the three publicly known incidents in three years came through someone else's software [18], and healthcare remains one of the most heavily targeted sectors for ransomware crews and extortion groups [17].
Watch for whether the vendor identifies itself, or whether another customer discloses first and names the product SickKids would not. Watch the affected-count and data-category disclosures when the review closes, and note the MOVEit precedent: in that case the CVE was public and customers could act [16]. Here they cannot.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
SickKids disclosed that the personal information of some current and former employees, as well as job applicants, was exposed in a cybersecurity incident, and says the breach stemmed from a flaw in third-party software.
ReportedView cited source - [3]
The hospital attributes the breach to a vulnerability in a third-party software application that it says is used by SickKids and other organizations, according to a media statement.
ReportedView cited source - [4]
The hospital has not named the vendor, the application, or the CVE involved.
ReportedView cited source - [5]
BleepingComputer writes that the hospital's framing appears to suggest there is a wider campaign against users of the same product.
- [6]
The external Careers website was temporarily affected and has since been safely restored, per the hospital's statement; it was temporarily pulled offline.
ReportedView cited source - [7]
Clinical systems and patient information were not affected, and patient care continued as usual, SickKids says.
ReportedView cited source
Sources & coverage · 4 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- bleepingcomputer.comAx Sharma2d agoSickKids data breach exposes employee and job applicant info
- sickkids.ca4h agoSickKids statement



