Canada’s Hospital for Sick Children attacked by cybercriminals again as employee data stolen
Canada's Hospital for Sick Children reported a data theft incident exposing current and former employee data via a third-party application.
The Hospital for Sick Children (SickKids), Canada's largest pediatric health center, disclosed that hackers stole personal information of current and former employees, job applicants, and SickKids Foundation staff, likely through a third-party software application. The attack briefly took down the hospital's careers website but did not involve clinical systems or patient information. Affected individuals were notified and offered two years of credit monitoring. The hospital was previously hit by ransomware in 2022.
Canada: Nipigon hospital hit by ransomware attack
Nipigon District Memorial Hospital in Ontario, Canada confirmed a ransomware attack disrupted its IT systems, possibly affecting some patient services.
Nipigon District Memorial Hospital in Nipigon, Ontario announced that a ransomware attack affected its information technology systems. The hospital described the event as a 'cyber security incident' and warned that some patient services may be impacted while it responds. Nipigon Mayor Suzanne Kukko commented on the incident to local media. No threat actor was named and no data exposure or leak was confirmed at the time of disclosure.
Ransomware group hijacks hospital system’s Facebook page amid ongoing cyberattack fallout
'The Gentlemen' ransomware group hijacked AnMed's Facebook page, claiming theft of 6TB of sensitive patient data during an ongoing cyberattack on the hospital system.
AnMed, a nonprofit medical system with four hospitals in Georgia and South Carolina, is still responding to a July 26 cyberattack involving malware, with 10 facilities remaining closed as of Monday. On Tuesday its Facebook page displayed unauthorized posts claiming 'The Gentlemen' ransomware group exfiltrated 6 terabytes of data, including records on sexual assault, mental health, abortions and harassment; AnMed said the claims are unverified and patient data impact has not been confirmed. The Gentlemen, believed founded by a former Qilin affiliate using the moniker 'hastalamuerte,' extorted 332 victims in the first five months of 2026 per CheckPoint and claimed 125 industrial attacks in Q2 2026 per Dragos. The group typically breaches networks through edge devices, credential brute-forcing and known vulnerabilities, and offers affiliates tools to disable EDR.