Toronto’s Hospital for Sick Children — SickKids — has been breached again, and this time the damage landed on the people who work there rather than the children they treat.
The hospital disclosed on August 20, 2026 that a cybersecurity incident stemming from a vulnerability in a third-party software application exposed personal information belonging to current and former employees and job applicants. The flawed application supported the hospital’s external careers website and certain Human Resources functions, including payroll. SickKids first identified the intrusion on July 9, 2026.
Clinical systems and patient records were not affected.
Three organizations, one HR platform
The blast radius extends past the hospital itself. SickKids confirmed that personal information belonging to current and former employees of three affiliated entities may have been exposed:
- SickKids — the hospital
- Boomerang Health — a SickKids-owned pediatric clinic
- The SickKids Foundation — the hospital’s fundraising arm
Job applicants who used the careers portal are also in scope. That last category is the one organizations consistently forget. An applicant tracking system is a repository of resumes, contact details, employment history, references, and — depending on how far a candidate got in the process — background check and identity documentation, all belonging to people who never became employees and who have no relationship with the organization that would prompt them to check for a notice.
SickKids has not disclosed what specific data elements were involved or how many people were affected. Potentially impacted individuals have been notified directly and offered 24 months of complimentary credit monitoring and identity protection.
The careers website is not a low-value asset
The instinct in most security programs is to rank the recruiting portal well below the EHR. In terms of patient safety, that is correct. In terms of data sensitivity, it is not.
A combined careers-and-HR platform sits on:
- Full legal names, home addresses, dates of birth
- Social Insurance Numbers, for anyone onboarded through it
- Banking details, where payroll functions are integrated
- Employment history and compensation
- Immigration and work authorization status
- In some configurations, health and accommodation information
That is a more complete identity theft package per record than most clinical datasets, and it is typically defended with a fraction of the controls. Externally facing by design, integrated to payroll by convenience, and owned by HR rather than by security — the recruiting stack is a structurally under-governed piece of infrastructure at almost every large employer.
The hospital’s own framing is notable: the vulnerability sat in a third-party application “used by SickKids and other organizations.” That phrasing points at a shared-platform flaw rather than a SickKids-specific misconfiguration, which means other customers of the same vendor are likely working through their own notification exercises now.
The second time in four years
SickKids was hit by a LockBit ransomware affiliate in December 2022, an attack that degraded clinical systems and lab result turnaround over the holidays and prompted LockBit’s operators to publicly apologize and issue a free decryptor — a rare and self-serving gesture from a group that had a stated rule against attacking children’s hospitals.
This is a different incident with a different profile. There is no ransomware, no operational disruption, no claim on a leak site, and no named threat actor. What connects them is the target class: pediatric hospitals hold enormous quantities of sensitive data across systems of wildly varying maturity, and they run on public-sector budgets that rarely fund security at the level the data warrants.
What this should change in your program
Inventory the HR stack as a crown jewel. Applicant tracking, HRIS, payroll, and benefits platforms should be classified alongside the systems you would call tier one. In most inventories they are not.
Scope third-party assessments to what the vendor actually touches. A careers portal reviewed as a marketing website gets a marketing website’s security review. If the same platform reaches into payroll, it inherits payroll’s risk classification and belongs in the same assessment tier as your financial systems.
Keep applicant retention short and enforced. Most organizations retain rejected candidate records indefinitely because nobody set a policy. Every year of retained applicant data is a year of breach exposure with zero business value attached.
Segment the external-facing recruiting front end from the internal HR back end. The value in this architecture is convenience; the cost is that an internet-reachable flaw reaches employee records. Where integration is required, it should be a constrained one-way sync rather than shared infrastructure.
Notify applicants like you notify employees. They are the population least likely to hear about the incident and most likely to be surprised by the exposure.
SickKids says the investigation is ongoing. The affected count, the data categories, and the name of the third-party vendor are all still outstanding.
Sources
- BleepingComputer — SickKids data breach exposes employee and job applicant info
- The Record — Canada’s Hospital for Sick Children attacked by cybercriminals again
- CP24 — SickKids responding to cybersecurity incident
- The Register — SickKids children’s hospital bandages up careers website
- Cybernews — SickKids breach exposes employee and applicant data



