Breaking
UMNO-PAS cooperation only to seize Anwar's power, using Malay unity as excuse – AmanahMalaysia knocked out of Merdeka Cup women's semifinalsOutrage as China programmer’s toilet death ruled non-work-related for being ‘not at desk’Social assistance spending rises 6.1% in 2025PalawanPay targets physical card rollout in Q4Kelas Sekejap expands AI learning app to schools and enterprisesGoogle offers 12-month free AI Plus subscription to Malaysian studentsPoverty rate falls to single digits in the Philippines as incomes outpace thresholdsChinese insurer Ping An eyes Hong Kong ETFs as Beijing greenlights cross-border investmentSickKids discloses data breach exposing employee and job applicant detailsGitLab’s critical CVE-2026-19478 is under active exploitation within days of disclosure.Khazanah affirms governance push after third-quarter board meetingQR code payments launched for ShopeePay users in ChinaBanjarbaru delays school start times as haze worsensLuxury sales drop more than 10% in China as tax crackdown bitesCDL net profit surges 230.7% in first half on Lumina Grand recognitionTrade Minister sets US$25 billion Trade Expo Indonesia 2026 targetTeladan Group swings to RM9.31 million profit in 2QFY2026 on higher progressive billingsAI Living @ i-City to launch in Shah Alam with four agenciesNevada approves 8,000 robotaxis for Tesla, Uber and WaymoUMNO-PAS cooperation only to seize Anwar's power, using Malay unity as excuse – AmanahMalaysia knocked out of Merdeka Cup women's semifinalsOutrage as China programmer’s toilet death ruled non-work-related for being ‘not at desk’Social assistance spending rises 6.1% in 2025PalawanPay targets physical card rollout in Q4Kelas Sekejap expands AI learning app to schools and enterprisesGoogle offers 12-month free AI Plus subscription to Malaysian studentsPoverty rate falls to single digits in the Philippines as incomes outpace thresholdsChinese insurer Ping An eyes Hong Kong ETFs as Beijing greenlights cross-border investmentSickKids discloses data breach exposing employee and job applicant detailsGitLab’s critical CVE-2026-19478 is under active exploitation within days of disclosure.Khazanah affirms governance push after third-quarter board meetingQR code payments launched for ShopeePay users in ChinaBanjarbaru delays school start times as haze worsensLuxury sales drop more than 10% in China as tax crackdown bitesCDL net profit surges 230.7% in first half on Lumina Grand recognitionTrade Minister sets US$25 billion Trade Expo Indonesia 2026 targetTeladan Group swings to RM9.31 million profit in 2QFY2026 on higher progressive billingsAI Living @ i-City to launch in Shah Alam with four agenciesNevada approves 8,000 robotaxis for Tesla, Uber and Waymo
Economy

SickKids discloses data breach exposing employee and job applicant details

The Hospital for Sick Children (SickKids) disclosed a cybersecurity incident that exposed personal information of current and former employees, as well as job applicants, due to a flaw in third-party software.

Source: BleepingComputer · August 21, 2026 at 10:31 AM · AI-assisted report

Single-source
SickKids discloses data breach exposing employee and job applicant details
Photo: GerifalteDelSabana / CC BY-SA 4.0

KUALA LUMPUR, 21 AUGUST 2026 —

Listen to this article

DomainFork Audio · read aloud

The Hospital for Sick Children (SickKids) disclosed a cybersecurity incident that exposed personal information of current and former employees, as well as job applicants, due to a flaw in third-party software.

Market Impact

The Toronto pediatric hospital said its clinical systems and patient records were untouched, but its public-facing Careers website was temporarily pulled offline. SickKids said the breach resulted in unauthorized access to employee data, attributing it to a vulnerability in a third-party software application used by the hospital and other organizations.

The hospital did not name the vendor, the application, or the CVE involved, though the framing suggests a wider campaign against users of the same product. The external Careers website was temporarily affected and has since been restored, according to the statement.

Clinical systems and patient information were not affected, and patient care continued as usual. After learning of the incident, SickKids launched an investigation with the help of outside cybersecurity experts. The findings indicate that personal information belonging to current and former SickKids, Boomerang (a SickKids-owned pediatric clinic), and SickKids Foundation employees, as well as SickKids job applicants, may have been exposed.

The hospital has not said what categories of data were involved, how many people are affected, or when the intrusion took place. Its review of the impacted information is ongoing, with individuals confirmed as affected to be notified directly. In the meantime, SickKids says it has alerted everyone potentially caught up in the incident out of caution, and is offering 24 months of complimentary credit monitoring and identity protection.

Job application portals are an unusually rich target for data thieves, as applicants routinely hand over full names, home addresses, phone numbers, employment histories, and in some jurisdictions government identifiers. That information is useful both for identity fraud and for building convincing social engineering pretexts against hospital staff.

This is not the first publicly known security incident to hit the hospital in recent years. In December 2022, SickKids was hit by a ransomware attack that disrupted internal systems, hospital phone lines, and its website, and caused delays in lab and imaging results.

The LockBit ransomware gang subsequently issued a rare public apology, saying the affiliate responsible had broken its rules against encrypting medical institutions, and handed over a free decryptor, though only after the hospital had spent nearly two weeks restoring systems on its own.

In September 2023, SickKids was among Ontario healthcare providers caught up in a breach at a third-party organization it shares perinatal and child health data with. That incident, which stemmed from mass exploitation of the MOVEit Transfer zero-day (CVE-2023-34362), exposed information on 3.4 million people, including names, home addresses, dates of birth, and health card numbers.

Healthcare remains one of the most heavily targeted sectors for both ransomware crews and data extortion groups. Pediatric hospitals in particular sit on decades' worth of sensitive records, which continues to make them attractive to attackers regardless of the ethical lines criminal operations claim to observe.

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. According to a third-party cybersecurity report, signature-based prevention fell to 50%.

Related: Kuala Lumpur

Reporting based on BleepingComputer. Figures and claims are subject to revision as the story develops. DomainFork publishes editorial context, not investment advice — see our editorial standards.