Desk live·
ForensicPost
Breaches/Healthcare/File 26-0820

SickKids Says a Careers-Site Flaw Exposed Staff and Applicant Data From 2016–2018

Toronto’s Hospital for Sick Children disclosed that a third-party flaw behind its careers website reached employee and job-applicant data — including people whose only contact was applying for a job eight years ago. Patient systems were untouched.

Constructed geometry · not a chart of case data
JurisdictionCanadaTorontothe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetSickKids workforce and applicants
ActorUnattributed
D. Kennedy10 min readConfidence: high3 sources reviewed

On 20 August 2026 the Hospital for Sick Children in Toronto disclosed unauthorised access to personal information of current and former employees and job applicants, traced to a vulnerability in a third-party software application supporting its external careers website and certain human-resources functions, including payroll. Staff of the hospital, its Boomerang Health clinic and the SickKids Foundation are in scope. Clinical systems and patient information were not affected.

A letter to affected staff, as reported, identifies 9 July as the date the intrusion was found and describes the exposed population as people who were part of the workforce between 12 December 2016 and 31 August 2018 — a window closing eight years before the breach.

The Window Is The Story

A 2016–2018 workforce cohort exposed in 2026 means the system behind a careers website was still holding identity-grade records on people whose employment — or whose unsuccessful application — ended most of a decade ago. Nobody in that cohort had any way to know the data was still there, and no relationship remained through which anyone would think to ask.

The corpus records at 25-0704 that workforce data is the least covered category in any disclosure regime, and at 25-0613 that staff records pool in exactly this kind of adjacent system. A job applicant is the extreme case: they handed over a CV, a home address and often references, were never hired, and remained a data subject of an organisation they never joined.

The Second Time For This Hospital

SickKids was hit by LockBit ransomware in December 2022, an incident the operation publicly apologised for and issued a free decryptor over. This event shares nothing with that one except the target: a children’s hospital is an organisation whose name produces headlines, and whose adjacent estate — careers sites, foundations, clinics — carries data protection obligations the clinical estate’s controls do not reach.

What Patient Care Not Being Affected Means Here

The hospital’s assurance about clinical systems is credible and worth taking at face value. It is also the only measure most coverage applies to a hospital incident, and by that measure nothing happened. What happened is that the people who care for patients — and thousands who once applied to — had identity data exposed through a system nobody would list among a hospital’s critical assets.

How we reported this

Compiled from the hospital’s public statement and contemporaneous reporting, including reporting of the letter sent to affected staff, listed below. The third-party application is not named by the hospital and is not named here. Affected counts were not published. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. SickKids employee information impacted by cybersecurity incidentSickKids
  2. Canada’s Hospital for Sick Children attacked by cybercriminals again as employee data stolenThe Record
  3. SickKids data breach exposes employee and job applicant infoBleepingComputer
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary