Breach

Hospital for Sick Children discloses employee data breach due to third-party software flaw

(Adobe Stock)

The Hospital for Sick Children (SickKids) has disclosed a cybersecurity incident that exposed the personal information of current and former employees, as well as job applicants. The breach is attributed to a vulnerability in a third-party software application used by the hospital, with further coverage provided by Bleeping Computer.

SickKids confirmed that clinical systems and patient records were not affected, though its public-facing Careers website was temporarily taken offline. The hospital is investigating the incident with external cybersecurity experts and has not yet disclosed the specific categories of data involved, the number of individuals affected, or the exact timeline of the intrusion. Affected individuals will be notified directly, and the hospital is offering 24 months of complimentary credit monitoring and identity protection.

Job application portals are a frequent target for data thieves due to the sensitive personal information they contain. This incident follows previous security events at SickKids, including a ransomware attack in December 2022 and a breach in September 2023 linked to a third-party data-sharing organization. The healthcare sector remains a prime target for cybercriminals due to the sensitive nature of patient data.

Source: Bleeping Computer

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Attack Vector

You can skip this ad in 5 seconds