Full research report
SickKids data breach exposes employee and job applicant info
Executive assessment
SickKids disclosed a new data breach on 20 August 2026, six weeks after identifying it on 9 July, in which an unnamed third-party software application gave attackers unauthorised access to HR, payroll, and careers-platform data. The affected data covers a specific archival window โ December 2016 to August 2018 โ suggesting a legacy or migrated system rather than live operational infrastructure, though employment and applicant records from that period remain valuable for identity fraud and social engineering. Despite CVE-2023-34362 appearing in the source material, this vulnerability belongs to the Cl0p-led MOVEit Transfer campaign of 2023, which affected SickKids in a separate breach; no CVE has been publicly attributed to the current incident. Multiple independent outlets corroborate the disclosure but add no technical specifics, as the hospital has deliberately withheld vendor, CVE, and actor details pending its ongoing investigation. Healthcare organisations using third-party HR, payroll, or applicant-tracking platforms should treat this as a signal to audit vendor patch status and inspect access logs, particularly for any platforms supporting externally-facing recruitment portals.
What happened
SickKids disclosed on 20 August 2026 that it had identified unauthorised access to a third-party software application on 9 July 2026. The affected system supported the hospital's external careers website and HR/payroll functions. Personal information of current and former employees, workers at the SickKids Foundation and affiliated Boomerang Health clinic, and job applicants may have been exposed. Clinical systems and patient records were not affected, and affected individuals are being notified with 24 months of credit monitoring offered.
Affected scope
Current and former employees of SickKids, SickKids Foundation, and Boomerang Health, as well as SickKids job applicants. Affected records cover a data window of 12 December 2016 through 31 August 2018, indicating a legacy or previously migrated HR/payroll system. The third-party vendor, total number of individuals affected, and specific data categories have not been publicly disclosed.
Technical assessment
SickKids attributed the breach to a vulnerability in a third-party software application used by multiple organisations, suggesting a broader supply-chain or multi-victim campaign. The affected platform handled the public-facing careers site and sensitive HR/payroll functions, making it a high-value target for credential and identity data. The specific vulnerability mechanism, CVE, and software vendor remain undisclosed, preventing independent technical assessment. The narrow historical data window (2016โ2018) suggests the compromised system stored archival rather than live operational records.
Recommended defensive actions
- Audit all third-party vendors handling HR, payroll, and recruitment data; obtain patch status confirmations and review contractual notification obligations.
- Review access logs for externally-facing HR and careers platforms covering the period prior to and around 9 July 2026 for anomalous query volumes or data-export activity.
- Patch all internet-facing MOVEit Transfer instances to the versions fixing CVE-2023-34362 (2021.0.6+, 2021.1.4+, 2022.0.4+, 2022.1.5+, or 2023.0.1+) if not already done.
- Monitor for spear-phishing and social engineering attempts targeting hospital staff and job applicants, whose employment histories and contact details may now be in attacker hands.
- Subscribe to security advisories for any workforce management, applicant tracking, or HR information system (HRIS) platforms in use, and enforce minimum patch SLAs in vendor contracts.
Uncertainties and evidence gaps
- The third-party software vendor and the underlying CVE for the August 2026 breach have not been publicly named; independent assessment of exposure scope is not possible.
- The number of individuals affected and specific data categories exposed (e.g., government identifiers, salary records, home addresses) have not been disclosed.
- No threat actor has been attributed to the August 2026 breach; it is unknown whether this is linked to a known ransomware, data-extortion, or espionage group.
- The specific data window of December 2016 โ August 2018 is unexplained; it may indicate a legacy system or archive, but the reason for this boundary has not been confirmed.
- CVE-2023-34362 appears in the source material as a stated CVE but relates to a separate September 2023 incident at SickKids; whether any MOVEit product is involved in the current breach has not been confirmed or denied.
Vulnerability flow
Defender-oriented path reconstructed only from sourced report findings. Unknown stages are omitted.
No CVE has been publicly identified for the August 2026 SickKids breach; CVE-2023-34362 (Progress MOVEit Transfer SQL injection) was previously exploited by the Cl0p ransomware group in a separate September 2023 campaign that also affected SickKids, and is referenced in source reporting only as historical context.
The investigation began with the BleepingComputer disclosure reporting a third-party software flaw as the breach cause, with no CVE or vendor named. Two independent outlets (The Record, The Register) were fetched and corroborated the timeline โ breach identified 9 July 2026, disclosed 20 August โ and confirmed HR/payroll systems were within scope alongside the careers site. The CP24 article, sourced from the hospital's own statement, added the specific data window of December 2016 to August 2018, pointing to a legacy system. Research into CVE-2023-34362 confirmed it belongs to the Cl0p MOVEit campaign of 2023, referenced in the BleepingComputer article as historical context for a prior SickKids breach, not the current event. No CVE, vendor, or actor has been confirmed for the August 2026 incident, making technical attribution a material gap.
- What are the full details of the August 2026 SickKids breach as reported by the primary outlet?Fetched the BleepingComputer article on the SickKids breach disclosure.bleepingcomputer.com โ
No CVE, vendor, or actor named for the current breach. Third-party software described generically. Clinical systems unaffected; careers site temporarily offline. 24-month credit monitoring offered. Article references the 2023 MOVEit breach as historical context only.
why Establishes primary disclosure facts and confirms that SickKids has deliberately withheld technical specifics, making independent source corroboration necessary.
- Do independent outlets provide additional technical detail or a different timeline?Fetched The Record's article on the same incident.therecord.media โ
Confirms breach identified 9 July 2026 and that the affected system included HR/payroll functions, not just the careers website. No CVE or vendor attribution added.
why Independent corroboration from a specialist outlet confirms the HR/payroll scope, ruling out a careers-website-only incident and raising the data sensitivity of the exposure.
- Does The Register provide any additional technical or actor attribution?Fetched The Register's coverage of the SickKids breach.theregister.com โ
Confirms vague hospital disclosure; no CVE, vendor, or actor named. Notes the hospital's deliberate non-disclosure of scale and specifics.
why Second independent outlet confirming the information vacuum; absence of attribution across three outlets increases confidence that no actor has been publicly named.
- What does the hospital's own statement say about the data scope and timeline?Fetched the CP24 article drawing on SickKids' media statement.cp24.com โ
Breach identified 9 July 2026; affected data covers 12 December 2016 through 31 August 2018, indicating a legacy or migrated HR/payroll system rather than a live operational platform.
why The specific historical data window is a material scoping detail that changes the threat model: attackers accessed archival records, not live identity data, though the content remains sensitive for identity fraud.
- Is CVE-2023-34362 the mechanism for the current breach, or is it historical context from the 2023 MOVEit campaign?Fetched the Fortinet advisory on CVE-2023-34362 and cross-referenced BleepingComputer's article text.fortinet.com โ
CVE-2023-34362 is a SQL injection in MOVEit Transfer (patched May 2023), exploited by Cl0p as a zero-day in 2023. The BleepingComputer article cites it only in relation to a prior September 2023 SickKids incident, not the current 2026 event.
why Separating these two incidents is critical: CVE-2023-34362 is accurately attributed to a historical breach, and no CVE has been confirmed for the August 2026 event.
- Is a public PoC for CVE-2023-34362 confirmed available?Fetched the Horizon3 GitHub repository linked in the deepdarkCTI record.github.com โ
Repository confirmed live; contains a verified Python PoC chaining SQL injection with a deserialisation flaw to achieve RCE against MOVEit Transfer.
why Confirms public exploit code exists and is maintained for CVE-2023-34362, consistent with its CISA KEV listing and EPSS score of 0.99934, and explains its continued prominence in threat-intelligence tracking.
- Does the deepdarkCTI record provide any new actor or 2026 campaign context for CVE-2023-34362?Fetched the deepdarkCTI most-exploited CVE list.raw.githubusercontent.com โ
CVE-2023-34362 listed as a widely exploited vulnerability (RCE in Progress MOVEit Transfer); no new 2026 campaign or additional actor attribution beyond the known Cl0p association.
why Confirms continued tracking of the CVE in threat-intelligence sources but provides no evidence linking it to the current SickKids breach.
Research coverage
All 68 registered source leaves were evaluated for this run: 61 completed, 0 were unavailable, 0 failed and 7 were disabled. For this story, 17 registered sources supplied useful evidence (2 primary, 13 corroborating, 2 contextual and 0 PoC/exploit references). 44 completed sources contained no matched information for this story.
Complete source-by-source audit 68 sources
| Source | Run result | Value | Why it was useful โ or not |
|---|---|---|---|
| BleepingComputernews | ok9 records | Primary evidence2 matched items | Published the source report used to frame and date the event. Supplied independent analysis opened and verified during focused research. |
| CISA KEVkev | ok1674 records | Primary evidence1 matched items | Confirmed that a related CVE is listed in CISA's Known Exploited Vulnerabilities catalogue. |
| CISA Alertsnews | ok empty0 records | Corroborating1 matched items | A page from this source was opened and verified during focused research. |
| deepdarkCTI Discorddeepdarkcti | ok7 records | Corroborating1 matched items | A page from this source was opened and verified during focused research. |
| deepdarkCTI exploitsdeepdarkcti | ok24 records | Corroborating1 matched items | A page from this source was opened and verified during focused research. |
| deepdarkCTI forumsdeepdarkcti | ok264 records | Corroborating1 matched items | A page from this source was opened and verified during focused research. |
| deepdarkCTI malware as a servicedeepdarkcti | ok7 records | Corroborating1 matched items | A page from this source was opened and verified during focused research. |
| deepdarkCTI malware samplesdeepdarkcti | ok3 records | Corroborating1 matched items | A page from this source was opened and verified during focused research. |
| deepdarkCTI marketsdeepdarkcti | ok127 records | Corroborating1 matched items | A page from this source was opened and verified during focused research. |
| deepdarkCTI phishingdeepdarkcti | ok19 records | Corroborating1 matched items | A page from this source was opened and verified during focused research. |
| deepdarkCTI ransomware gangsdeepdarkcti | ok686 records | Corroborating1 matched items | A page from this source was opened and verified during focused research. |
| deepdarkCTI RATsdeepdarkcti | ok1 records | Corroborating1 matched items | A page from this source was opened and verified during focused research. |
| deepdarkCTI Telegram infostealerdeepdarkcti | ok130 records | Corroborating1 matched items | A page from this source was opened and verified during focused research. |
| deepdarkCTI Telegram threat actorsdeepdarkcti | ok1009 records | Corroborating1 matched items | A page from this source was opened and verified during focused research. |
| deepdarkCTI Twitter threat actorsdeepdarkcti | ok39 records | Corroborating1 matched items | A page from this source was opened and verified during focused research. |
| deepdarkCTI CVE most exploiteddeepdarkcti | ok94 records | Context2 matched items | Provided lower-confidence OSINT context matched to an explicit CVE. Supplied OSINT or actor context opened and verified during focused research. |
| FIRST EPSSepss | ok7871 records | Context1 matched items | Added exploitation-probability context; EPSS does not itself prove exploitation. |
| AlienVault OTXdark_web | ok10 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| CIRCL CVEcve | ok30 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Cisco PSIRTvendor_advisory | ok5332 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Cisco Talosnews | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| DNSDumpster domain IOC enrichmentresearch | ok1 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Exploit-DBexploit_reference | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| Fortinet PSIRTvendor_advisory | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| GitHub topic: cveresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| GitHub topic: exploitresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| GitHub topic: penetration-testingresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| GitHub topic: pocresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| GitHub topic: vulnerabilityresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| GreyNoiseexploit_reference | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| KrebsOnSecuritynews | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| LinkedIn RSS proxy feeds (disabled)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| MalwareBazaardark_web | ok4 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #cveresearch | ok20 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #cybersecurityresearch | ok10 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #exploitresearch | ok11 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #infosecresearch | ok18 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #malwareresearch | ok20 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #ransomwareresearch | ok19 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #threatintelresearch | ok14 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #vulnerabilityresearch | ok20 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Metasploit module metadataexploit_reference | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| Microsoft MSRCvendor_advisory | ok1590 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Microsoft Securitynews | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| MISP Galaxyresearch | ok2 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| MISP threat actor galaxyactor | ok0 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| NVDcve | ok900 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Palo Alto Networks PSIRTvendor_advisory | ok25 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| ProjectDiscovery nuclei templatesexploit_reference | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| Rapid7news | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| Reddit r/AskNetsec (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/cybersecurity (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/malware (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/netsec (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/ReverseEngineering (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| SANS ISCnews | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| Shadowserver public aggregate honeypot observationsexploit_reference | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| Shodanresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| Sigma Rulesresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| Sophos IOCsresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| The Hacker Newsnews | ok7 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| ThreatFoxthreat_intelligence | ok100 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| UK NCSCnews | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| Unit42 IOCsresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| URLhausdark_web | ok10 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| VirusTotal Community IOC enrichmentresearch | ok3 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| VulnCheck KEVkev | ok500 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Vulnerability Lookupcve | ok30 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
Additional verified pages 6 opened outside the registered collection
Vulnerability & exploitation2
Reporting-linked PoC claims1
Linked by reporting but not validated as PoC by the configured exploit indexes.
OSINT / dark-web chatter1
PoC & exploit code1
Live, verified PoC chaining MOVEit SQL injection with a deserialisation flaw for RCE; from the 2023 campaign.
Vendor & gov advisories1
Covers affected MOVEit versions, exploitation mechanism, and patch guidance for CVE-2023-34362.
OSINT / dark-web chatter1
Community-maintained record confirming continued dark-web tracking of CVE-2023-34362; no new 2026 campaign attributed.
Analysis & research3
Independent corroboration; confirms breach identified 9 July 2026 and that HR/payroll systems were within scope.
Second independent outlet confirming scope and hospital's deliberate non-disclosure of vendor and CVE details.
Primary reporting with historical breach context and analysis of why job-application portals are high-value targets.