Canadian SickKids hospital hit again by cyberattacks, more data stolen
SickKids hospital in Canada hit by third‑party software vulnerability, exposing employee data Clinical systems and patient records unaffected; patient care continued without disruption Affected staff and applicants offered 24 months of free credit monitoring and identity protection The Hospital for Sick Children, a major pediatric hospital in Canada, suffered a cyberattack that affected parts of its website, and resulted in the loss of some employee personal information.
In an announcement published on its website, the organization (also known as SickKids) said the unnamed attackers abused a “vulnerability in a third-party software application used by SickKids and other organizations.” The announcement did not say exactly which app was used in the attack, or what the vulnerability was, but stressed that clinical systems and patient information were not affected.
“Patient care has continued as usual”, it added.
This is not SickKids' first attack After launching an investigation, SickKids learned that personal information of some former and current employees working at SickKids, Boomerang, and SickKids Foundation, as well as SickKids job applications, was exposed.
It did not detail the nature of the exposed information, or how many people are affected.
Whatever that number is, those people have been offered 24 months of complimentary credit monitoring and identity protection services, for free.
“We remain committed to maintaining strong protections and continuously enhancing our cybersecurity measures to help protect the information entrusted to us,” the company concluded.
Ironically, SickKids was also committed in late 2022 and early 2023, when it was struck by LockBit and had its systems locked down by the ransomware threat actor.
While, in that incident, LockBit apologized, gave the decryptor away for free, excommunicated the affiliate responsible, and did not mention any stolen data, by late 2022 double extortion attacks were standard practice, meaning data was likely exfiltrated then, as well.
At the time, LockBit was one of the most active and most dangerous ransomware operators.
In early 2024, its operations were severely disrupted through Operation Cronos, but it seems the group is making a comeback.
There are reports from late 2025 of LockBit 5.0 claims , including a purported attack on U.S Bank , but the news is yet to be confirmed.
Via The Record
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.