ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Toronto’s SickKids reports data security incident involving employee information

Toronto-based pediatric hospital SickKids has disclosed a significant data security incident that compromised sensitive personal information belonging to its current and former employees.

Linked InXFacebook
bookmark_borderSave to Library

Toronto-based pediatric hospital SickKids has reported a significant data security incident that exposed sensitive personal information belonging to its current and former employees.

 

The Hospital for Sick Children (SickKids) is a leading pediatric academic health centre in Toronto, Canada, affiliated with the University of Toronto. As the country’s largest and most research-intensive children’s hospital, it is globally recognised for delivering specialised care, advancing medical research, driving innovation, and shaping the future of pediatric healthcare.

 

In a data security incident notice published on its website, SickKids said that it recemntly identified unauthorised access to its internal network. The healthcare provider immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.

 

It also took steps to secure the affected network and notified relevant law enforcement authorities about the incident.

 

“The Hospital for Sick Children (SickKids) was recently targeted in a cybersecurity incident that resulted in unauthorized access to personal information of some of our current and former employees. The incident temporarily affected the external Careers website, which has since been safely restored, and is linked to a vulnerability in a third-party software application used by SickKids and other organiSations,” SickKids said.

 

While the healthcare provider did not disclose specific details about the compromised data, it said the personal information of some current and former SickKids, Boomerang, and SickKids Foundation employees, and applicants, was affected in the incident.

 

SickKids, however, confirmed that its clinical systems and patient data remained unaffected, with patient care continuing without disruption.

 

The healthcare provider said its assessment of the affected information is still underway. Individuals confirmed to have been impacted will be contacted directly. As a precaution, however, all potentially affected individuals have been notified and offered 24 months of complimentary credit monitoring and identity protection services.

 

In December 2022, SickKids was targeted by a ransomware attack that caused significant disruptions across the hospital’s digital infrastructure. The incident affected internal systems, hospital phone lines, and the organisation’s website, while also leading to delays in the processing and delivery of laboratory and medical imaging results. The cyber attack created operational challenges for staff and healthcare services as the hospital worked to restore affected systems and maintain patient care.

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543