cybercrime

Toronto org says it wasn’t the only one to be affected by the third-party software vulnerability

Toronto’s Hospital for Sick Children, commonly referred to as SickKids, says the data of current and former staff, as well as job applicants, was exposed after an intruder exploited a security flaw in a third-party software application used by the hospital.SickKids, which may ring a bell for those who have kept close tabs on ransomware news in recent years, said the intrusion affected its external careers site, which has now been restored.“Clinical systems and patient information were not affected, and patient care has continued as usual,” it said, after explaining that the break-in was a result of a vulnerability in a “third-party software application used by SickKids and other organizations."

Current and former employees of SickKids, the SickKids Foundation, and the hospital’s Vaughan, Ontario-based Boomerang clinic may all be affected, as were SickKids job applicants.

The hospital did not comment on the scale of the breach, but said those affected will be offered the usual identity and credit monitoring services.“Our review of the impacted information is ongoing. Individuals determined to have been impacted will be notified directly, though, out of an abundance of caution, all potentially impacted individuals have been alerted and offered 24 months of complimentary credit monitoring and identity protection services. “Safeguarding the privacy and security of personal information is a responsibility SickKids takes seriously. We remain committed to maintaining strong protections and continuously enhancing our cybersecurity measures to help protect the information entrusted to us.”