Toronto's Hospital for Sick Children, known as SickKids, has disclosed a cybersecurity incident involving personal information tied to some current and former employees and job applicants, according to BleepingComputer. The hospital attributed the exposure to a vulnerability in third-party software, but has not publicly named the vendor, the application, or the specific vulnerability involved. The current scope, based on the hospital's statements cited by BleepingComputer, is workforce and recruiting data rather than patient-care systems. SickKids said clinical systems and patient information were not affected, and that patient care continued as usual. The hospital's public-facing Careers website was temporarily affected during the response and has since been restored, according to the report. SickKids said it brought in outside cybersecurity experts after learning of the incident and is continuing to review what information was affected. The potentially exposed population includes current and former employees of SickKids, Boomerang — a SickKids-owned pediatric clinic — and the SickKids Foundation, as well as people who applied for jobs at SickKids, BleepingComputer reports. The hospital has not said how many people may be affected, what specific categories of personal information were involved, or when the intrusion occurred. SickKids is notifying individuals it confirms were affected directly. In the meantime, BleepingComputer reports, the hospital has alerted everyone who may have been caught up in the incident out of caution and is offering 24 months of complimentary credit monitoring and identity protection. The third-party angle is the unresolved operational issue. BleepingComputer notes that SickKids described the software as used by other organizations, language that may point to broader exposure among customers of the same product. But with no vendor, product name, or CVE disclosed, there is not yet enough public information to determine whether this was an isolated compromise or part of a wider exploitation campaign. The incident also follows earlier security events involving the hospital. BleepingComputer notes that SickKids was hit by a ransomware attack in December 2022 that disrupted internal systems, phone lines, the website, and some lab and imaging result workflows. The report also cites a 2023 third-party breach involving Ontario healthcare providers and MOVEit Transfer exploitation, which affected shared perinatal and child health data. For now, the hospital's most important claim is that the breach did not affect clinical operations or patient records. The remaining risk sits with the individuals whose employment or application information may have been exposed, and with other organizations that may rely on the same unnamed third-party software. Who benefits: Affected individuals benefit from direct notification and the offered 24 months of credit monitoring and identity protection. Security teams at organizations using similar third-party software may also benefit if the vendor or vulnerability is later identified. Who's exposed: Current and former SickKids, Boomerang, and SickKids Foundation employees, along with SickKids job applicants, are the groups SickKids says may have been affected. The precise data categories and number of individuals remain undisclosed.