Full research report

SickKids data breach exposes employee and job applicant info

Original reporting โ†—
โ˜… Threat intelligence assessment medium confidence

Executive assessment

SickKids disclosed a new data breach on 20 August 2026, six weeks after identifying it on 9 July, in which an unnamed third-party software application gave attackers unauthorised access to HR, payroll, and careers-platform data. The affected data covers a specific archival window โ€“ December 2016 to August 2018 โ€“ suggesting a legacy or migrated system rather than live operational infrastructure, though employment and applicant records from that period remain valuable for identity fraud and social engineering. Despite CVE-2023-34362 appearing in the source material, this vulnerability belongs to the Cl0p-led MOVEit Transfer campaign of 2023, which affected SickKids in a separate breach; no CVE has been publicly attributed to the current incident. Multiple independent outlets corroborate the disclosure but add no technical specifics, as the hospital has deliberately withheld vendor, CVE, and actor details pending its ongoing investigation. Healthcare organisations using third-party HR, payroll, or applicant-tracking platforms should treat this as a signal to audit vendor patch status and inspect access logs, particularly for any platforms supporting externally-facing recruitment portals.

What happened

SickKids disclosed on 20 August 2026 that it had identified unauthorised access to a third-party software application on 9 July 2026. The affected system supported the hospital's external careers website and HR/payroll functions. Personal information of current and former employees, workers at the SickKids Foundation and affiliated Boomerang Health clinic, and job applicants may have been exposed. Clinical systems and patient records were not affected, and affected individuals are being notified with 24 months of credit monitoring offered.

Affected scope

Current and former employees of SickKids, SickKids Foundation, and Boomerang Health, as well as SickKids job applicants. Affected records cover a data window of 12 December 2016 through 31 August 2018, indicating a legacy or previously migrated HR/payroll system. The third-party vendor, total number of individuals affected, and specific data categories have not been publicly disclosed.

Technical assessment

SickKids attributed the breach to a vulnerability in a third-party software application used by multiple organisations, suggesting a broader supply-chain or multi-victim campaign. The affected platform handled the public-facing careers site and sensitive HR/payroll functions, making it a high-value target for credential and identity data. The specific vulnerability mechanism, CVE, and software vendor remain undisclosed, preventing independent technical assessment. The narrow historical data window (2016โ€“2018) suggests the compromised system stored archival rather than live operational records.

Recommended defensive actions

  1. Audit all third-party vendors handling HR, payroll, and recruitment data; obtain patch status confirmations and review contractual notification obligations.
  2. Review access logs for externally-facing HR and careers platforms covering the period prior to and around 9 July 2026 for anomalous query volumes or data-export activity.
  3. Patch all internet-facing MOVEit Transfer instances to the versions fixing CVE-2023-34362 (2021.0.6+, 2021.1.4+, 2022.0.4+, 2022.1.5+, or 2023.0.1+) if not already done.
  4. Monitor for spear-phishing and social engineering attempts targeting hospital staff and job applicants, whose employment histories and contact details may now be in attacker hands.
  5. Subscribe to security advisories for any workforce management, applicant tracking, or HR information system (HRIS) platforms in use, and enforce minimum patch SLAs in vendor contracts.

Uncertainties and evidence gaps

  • The third-party software vendor and the underlying CVE for the August 2026 breach have not been publicly named; independent assessment of exposure scope is not possible.
  • The number of individuals affected and specific data categories exposed (e.g., government identifiers, salary records, home addresses) have not been disclosed.
  • No threat actor has been attributed to the August 2026 breach; it is unknown whether this is linked to a known ransomware, data-extortion, or espionage group.
  • The specific data window of December 2016 โ€“ August 2018 is unexplained; it may indicate a legacy system or archive, but the reason for this boundary has not been confirmed.
  • CVE-2023-34362 appears in the source material as a stated CVE but relates to a separate September 2023 incident at SickKids; whether any MOVEit product is involved in the current breach has not been confirmed or denied.

Vulnerability flow

Defender-oriented path reconstructed only from sourced report findings. Unknown stages are omitted.

AccessExternally accessible third-party application reachable via the public internet (supporting a careers website and HR/payroll functions)
ComponentUnnamed third-party HR, payroll, and applicant-tracking platform
MechanismUnspecified vulnerability in a third-party application; no CVE or technical mechanism has been publicly disclosed by SickKids or identified in independent reporting
ImpactUnauthorised read access to employment records and job-applicant data covering December 2016 โ€“ August 2018; data suitable for identity fraud and targeted social engineering against hospital staff
DetectionAnomalous access to HR and careers platform data; SickKids identified the incident on 9 July 2026, but specific detection signals have not been publicly described
MitigationNo public patch or mitigation has been named for the current breach; SickKids has engaged external cybersecurity experts and has restored the careers website
Exploitation status

No CVE has been publicly identified for the August 2026 SickKids breach; CVE-2023-34362 (Progress MOVEit Transfer SQL injection) was previously exploited by the Cl0p ransomware group in a separate September 2023 campaign that also affected SickKids, and is referenced in source reporting only as historical context.

The investigation began with the BleepingComputer disclosure reporting a third-party software flaw as the breach cause, with no CVE or vendor named. Two independent outlets (The Record, The Register) were fetched and corroborated the timeline โ€“ breach identified 9 July 2026, disclosed 20 August โ€“ and confirmed HR/payroll systems were within scope alongside the careers site. The CP24 article, sourced from the hospital's own statement, added the specific data window of December 2016 to August 2018, pointing to a legacy system. Research into CVE-2023-34362 confirmed it belongs to the Cl0p MOVEit campaign of 2023, referenced in the BleepingComputer article as historical context for a prior SickKids breach, not the current event. No CVE, vendor, or actor has been confirmed for the August 2026 incident, making technical attribution a material gap.

  1. What are the full details of the August 2026 SickKids breach as reported by the primary outlet?
    Fetched the BleepingComputer article on the SickKids breach disclosure.
    bleepingcomputer.com โ†—

    No CVE, vendor, or actor named for the current breach. Third-party software described generically. Clinical systems unaffected; careers site temporarily offline. 24-month credit monitoring offered. Article references the 2023 MOVEit breach as historical context only.

    why Establishes primary disclosure facts and confirms that SickKids has deliberately withheld technical specifics, making independent source corroboration necessary.

  2. Do independent outlets provide additional technical detail or a different timeline?
    Fetched The Record's article on the same incident.
    therecord.media โ†—

    Confirms breach identified 9 July 2026 and that the affected system included HR/payroll functions, not just the careers website. No CVE or vendor attribution added.

    why Independent corroboration from a specialist outlet confirms the HR/payroll scope, ruling out a careers-website-only incident and raising the data sensitivity of the exposure.

  3. Does The Register provide any additional technical or actor attribution?
    Fetched The Register's coverage of the SickKids breach.
    theregister.com โ†—

    Confirms vague hospital disclosure; no CVE, vendor, or actor named. Notes the hospital's deliberate non-disclosure of scale and specifics.

    why Second independent outlet confirming the information vacuum; absence of attribution across three outlets increases confidence that no actor has been publicly named.

  4. What does the hospital's own statement say about the data scope and timeline?
    Fetched the CP24 article drawing on SickKids' media statement.
    cp24.com โ†—

    Breach identified 9 July 2026; affected data covers 12 December 2016 through 31 August 2018, indicating a legacy or migrated HR/payroll system rather than a live operational platform.

    why The specific historical data window is a material scoping detail that changes the threat model: attackers accessed archival records, not live identity data, though the content remains sensitive for identity fraud.

  5. Is CVE-2023-34362 the mechanism for the current breach, or is it historical context from the 2023 MOVEit campaign?
    Fetched the Fortinet advisory on CVE-2023-34362 and cross-referenced BleepingComputer's article text.
    fortinet.com โ†—

    CVE-2023-34362 is a SQL injection in MOVEit Transfer (patched May 2023), exploited by Cl0p as a zero-day in 2023. The BleepingComputer article cites it only in relation to a prior September 2023 SickKids incident, not the current 2026 event.

    why Separating these two incidents is critical: CVE-2023-34362 is accurately attributed to a historical breach, and no CVE has been confirmed for the August 2026 event.

  6. Is a public PoC for CVE-2023-34362 confirmed available?
    Fetched the Horizon3 GitHub repository linked in the deepdarkCTI record.
    github.com โ†—

    Repository confirmed live; contains a verified Python PoC chaining SQL injection with a deserialisation flaw to achieve RCE against MOVEit Transfer.

    why Confirms public exploit code exists and is maintained for CVE-2023-34362, consistent with its CISA KEV listing and EPSS score of 0.99934, and explains its continued prominence in threat-intelligence tracking.

  7. Does the deepdarkCTI record provide any new actor or 2026 campaign context for CVE-2023-34362?
    Fetched the deepdarkCTI most-exploited CVE list.
    raw.githubusercontent.com โ†—

    CVE-2023-34362 listed as a widely exploited vulnerability (RCE in Progress MOVEit Transfer); no new 2026 campaign or additional actor attribution beyond the known Cl0p association.

    why Confirms continued tracking of the CVE in threat-intelligence sources but provides no evidence linking it to the current SickKids breach.

ActorsCl0p / TA505 (attributed to the historical September 2023 MOVEit campaign at SickKids; not attributed to the current 2026 breach)
TargetsThe Hospital for Sick Children (SickKids)SickKids FoundationBoomerang Health
Related CVEs CVE-2023-34362

Research coverage

All 68 registered source leaves were evaluated for this run: 61 completed, 0 were unavailable, 0 failed and 7 were disabled. For this story, 17 registered sources supplied useful evidence (2 primary, 13 corroborating, 2 contextual and 0 PoC/exploit references). 44 completed sources contained no matched information for this story.

Primary evidence Independent corroboration Operational context PoC reference Checked โ€” no match Unavailable Failed Disabled
Complete source-by-source audit 68 sources
SourceRun resultValueWhy it was useful โ€” or not
BleepingComputernews ok9 records Primary evidence2 matched items Published the source report used to frame and date the event. Supplied independent analysis opened and verified during focused research.
CISA KEVkev ok1674 records Primary evidence1 matched items Confirmed that a related CVE is listed in CISA's Known Exploited Vulnerabilities catalogue.
CISA Alertsnews ok empty0 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI Discorddeepdarkcti ok7 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI exploitsdeepdarkcti ok24 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI forumsdeepdarkcti ok264 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI malware as a servicedeepdarkcti ok7 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI malware samplesdeepdarkcti ok3 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI marketsdeepdarkcti ok127 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI phishingdeepdarkcti ok19 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI ransomware gangsdeepdarkcti ok686 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI RATsdeepdarkcti ok1 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI Telegram infostealerdeepdarkcti ok130 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI Telegram threat actorsdeepdarkcti ok1009 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI Twitter threat actorsdeepdarkcti ok39 records Corroborating1 matched items A page from this source was opened and verified during focused research.
deepdarkCTI CVE most exploiteddeepdarkcti ok94 records Context2 matched items Provided lower-confidence OSINT context matched to an explicit CVE. Supplied OSINT or actor context opened and verified during focused research.
FIRST EPSSepss ok7871 records Context1 matched items Added exploitation-probability context; EPSS does not itself prove exploitation.
AlienVault OTXdark_web ok10 records Checked โ€” no match The source completed, but none of its retained records matched this story.
CIRCL CVEcve ok30 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Cisco PSIRTvendor_advisory ok5332 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Cisco Talosnews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
DNSDumpster domain IOC enrichmentresearch ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Exploit-DBexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Fortinet PSIRTvendor_advisory disabled Disabled Disabled in the source registry; no check was attempted.
GitHub topic: cveresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GitHub topic: exploitresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GitHub topic: penetration-testingresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GitHub topic: pocresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GitHub topic: vulnerabilityresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GreyNoiseexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
KrebsOnSecuritynews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
LinkedIn RSS proxy feeds (disabled)research disabled Disabled Disabled in the source registry; no check was attempted.
MalwareBazaardark_web ok4 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #cveresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #cybersecurityresearch ok10 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #exploitresearch ok11 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #infosecresearch ok18 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #malwareresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #ransomwareresearch ok19 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #threatintelresearch ok14 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #vulnerabilityresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Metasploit module metadataexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Microsoft MSRCvendor_advisory ok1590 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Microsoft Securitynews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
MISP Galaxyresearch ok2 records Checked โ€” no match The source completed, but none of its retained records matched this story.
MISP threat actor galaxyactor ok0 records Checked โ€” no match The source completed, but none of its retained records matched this story.
NVDcve ok900 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Palo Alto Networks PSIRTvendor_advisory ok25 records Checked โ€” no match The source completed, but none of its retained records matched this story.
ProjectDiscovery nuclei templatesexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Rapid7news ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Reddit r/AskNetsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/cybersecurity (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/malware (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/netsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/ReverseEngineering (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
SANS ISCnews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Shadowserver public aggregate honeypot observationsexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Shodanresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Sigma Rulesresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Sophos IOCsresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
The Hacker Newsnews ok7 records Checked โ€” no match The source completed, but none of its retained records matched this story.
ThreatFoxthreat_intelligence ok100 records Checked โ€” no match The source completed, but none of its retained records matched this story.
UK NCSCnews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Unit42 IOCsresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
URLhausdark_web ok10 records Checked โ€” no match The source completed, but none of its retained records matched this story.
VirusTotal Community IOC enrichmentresearch ok3 records Checked โ€” no match The source completed, but none of its retained records matched this story.
VulnCheck KEVkev ok500 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Vulnerability Lookupcve ok30 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Additional verified pages 6 opened outside the registered collection
Vulnerability & exploitation2
CVE-2023-34362 CISA KEV Progress MOVEit Transfer ยท added 2023-06-02 ยท used in ransomware CISA catalog โ†—
CVE-2023-34362 EPSS 99.9% 100th percentile exploitation probability
Reporting-linked PoC claims1
https://github.com/horizon3ai/CVE-2023-34362 github.com โ†—

Linked by reporting but not validated as PoC by the configured exploit indexes.

OSINT / dark-web chatter1
deepdarkCTI: CVE-2023-34362 (Progress MOVEit) raw.githubusercontent.com โ†—
PoC & exploit code1
horizon3ai/CVE-2023-34362 โ€“ MOVEit Transfer PoC github.com โ†—

Live, verified PoC chaining MOVEit SQL injection with a deserialisation flaw for RCE; from the 2023 campaign.

Vendor & gov advisories1
FortiGuard Labs: MOVEit Transfer Critical Vulnerability CVE-2023-34362 Exploited as a 0-Day fortinet.com โ†—

Covers affected MOVEit versions, exploitation mechanism, and patch guidance for CVE-2023-34362.

OSINT / dark-web chatter1
deepdarkCTI: CVE-2023-34362 listed in most-exploited CVEs raw.githubusercontent.com โ†—

Community-maintained record confirming continued dark-web tracking of CVE-2023-34362; no new 2026 campaign attributed.

Analysis & research3
Canada's Hospital for Sick Children attacked by cybercriminals again โ€“ The Record therecord.media โ†—

Independent corroboration; confirms breach identified 9 July 2026 and that HR/payroll systems were within scope.

SickKids children's hospital bandages up careers website after intruder breaks in โ€“ The Register theregister.com โ†—

Second independent outlet confirming scope and hospital's deliberate non-disclosure of vendor and CVE details.

SickKids data breach exposes employee and job applicant info โ€“ BleepingComputer bleepingcomputer.com โ†—

Primary reporting with historical breach context and analysis of why job-application portals are high-value targets.