SickKids says a third-party software flaw led to unauthorized access involving employee and job applicant information. Here’s who was affected, why it matters, and how you can protect yourself online.
Table of Contents
What Happened?
SickKids said a weakness in third-party software allowed unauthorized access to information connected to its Careers website. The hospital temporarily took the site offline and later restored it.
Clinical systems and patient records were not affected, and patient care continued as usual. SickKids is still investigating the incident with outside cybersecurity experts.
The hospital has not said how many people were affected or exactly what information was involved.
Personal information can remain useful to scammers long after a breach. It may help them make phishing emails, fake calls, or identity theft attempts more convincing.
Many people also do not know their information was leaked in another incident until suspicious activity appears. Checking for leaks can help you notice problems earlier.
If you are unsure whether your information was leaked, automatic monitoring can help. Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.
Who Was Affected and What Information Was Involved?
The incident may affect current and former SickKids employees, job applicants, and workers connected to two related organizations.
Those include Boomerang — a SickKids-owned pediatric clinic — and SickKids Foundation.
SickKids has not publicly shared the specific types of personal information involved. It also has not said how many people were affected.
The hospital says patient information and clinical systems were not affected.
SickKids has alerted people who may be involved. It is also offering 24 months of complimentary credit monitoring and identity protection.
Futureproof scans your data for leaks and shows exactly how to close security gaps — before scammers find them first.
Check my safetyHow a Third-Party Software Flaw Led to the SickKids Breach
SickKids says the breach came from a vulnerability in third-party software used by the hospital and other organizations.
A software vulnerability is a security weakness that criminals may use to enter a system or access information.
However, SickKids has not named the software company, the affected application, or the specific security flaw.
The hospital also has not shared when the unauthorized access began or how long it lasted.

At Futureproof, Kevin explains digital safety in simple words, with clear tips and zero fluff. He holds a degree in information technology and studies fraud trends to keep his tips up-to-date.
In his free time, Kevin plays with his cat, enjoys board-game nights, and hunts for New York’s best cinnamon rolls.
