Skip to content
feed: live
>_0dayNews
ransomware
● Breaking

SickKids Hit Again: Data Theft via Third-Party App

SickKids confirms employee data stolen via a third-party software application. Second major incident since a 2022 ransomware attack disabled the Toronto hospital's clinical systems.

SickKids Hit Again: Data Theft via Third-Party App
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
airgapMorgan "airgap" Reyes·Published ·1 min read

Data theft confirmed. The Hospital for Sick Children (SickKids) in Toronto released a statement Thursday disclosing a data theft incident the hospital attributes to a third-party software application. Employee data is affected. Investigation ongoing.

The Record reported the disclosure Thursday. Per the hospital’s statement: its own systems, networks, and data repositories show no signs of direct compromise. The breach vector is the third-party application — vendor identity and application name not yet publicly named. Scope of the employee data exposure still being assessed.

This is SickKids’ second significant incident. A 2022 ransomware attack disabled some of the hospital’s clinical and corporate systems; recovery took weeks. That was direct network penetration. This is lateral — access through a vendor software integration. The outcome is the same: data is out.

Confirmed:

  • Employee data stolen
  • Incident attributed to a third-party software application
  • Hospital’s own systems, networks, and data repositories: no evidence of direct compromise

Unconfirmed: vendor identity, application name, whether patient records are in scope. No threat actor has claimed responsibility at time of publication.

The vendor access pathway into healthcare employee records is not novel. Third-party software with privileged access to HR and administrative systems is a consistent attack surface in this sector — and an undermonitored one. Whether SickKids is an isolated target or part of a broader campaign against the same vendor remains unknown until the vendor is named.

Watch for follow-up disclosures. Healthcare incidents that begin with “employee data” often expand in scope.


Related: Clop Claims GE and Philips; Both Investigating · ShinyHunters Targets Healthcare SSO, Health-ISAC Warns · Ransomware Gang Seizes Hospital’s Facebook Page

Found this useful? Share it.