Toronto children's hospital breached again, employee data stolen
The Hospital for Sick Children disclosed a data theft incident linked to third-party software, two years after a disruptive ransomware attack.
The Hospital for Sick Children in Toronto confirmed Thursday that employee data was stolen in a cyberattack traced to a third-party software application. The institution released a statement warning staff and stakeholders of the breach.
The hospital was previously hit by a ransomware incident in 2022 that disabled critical systems. That attack disrupted clinical operations and forced the pediatric facility to manage patient care under degraded IT conditions. The recurrence underscores persistent exposure in healthcare infrastructure, particularly through supply chain and vendor access points.
Third-party software remains a common vector for data theft. Attackers exploit trusted integrations to bypass perimeter defenses and exfiltrate sensitive information without triggering internal alarms. Employee data — including credentials, contact details, and potentially payroll records — can be weaponized for follow-on social engineering, identity fraud, or extortion campaigns.
- 01Healthcare institutions face compounding risk from vendor software exploited by threat actors.
- 02Employee data theft enables credential abuse, phishing, and follow-on attacks against the organization.
- 03Repeat breaches at critical infrastructure sites indicate systemic gaps in third-party oversight.
- 04Patients and families may face indirect risk if stolen employee credentials unlock clinical systems.
Boston Scientific confirms cyberattack disrupting medical device shipments
The Massachusetts-based medical device manufacturer disclosed the incident in SEC filings Tuesday, warning of operational impact to its supply chain.
US sanctions Iranian nationals after UK power plant intrusion
Treasury action follows disclosure of cyber operation targeting British energy facility, marking coordinated transatlantic response to infrastructure threats.
Supply-chain attack embeds proxy botnet in Android car head units
Legitimate device-update app compromised to spread malware that turns in-vehicle systems into proxy nodes and ad-fraud platforms.