Intelligent CISO Issue 102 | Page 35

UPDATES

threat

UPDATES
CANADA
The Hospital for Sick Children( SickKids) in Toronto has confirmed that personal information belonging to some current and former employees was accessed during a cybersecurity incident.
The incident temporarily affected the hospital’ s external Careers website, which has since been restored. SickKids said the incident was linked to a vulnerability in a third-party software application used by the hospital and other organisations.
Clinical systems and patient information were not affected by the incident and patient care continued as normal, according to the hospital.
SickKids launched an investigation after discovering the incident and brought in external cybersecurity specialists to support its response. The investigation has determined that personal information relating to some current and former SickKids employees may have been affected. Information relating to some current and former employees of Boomerang and SickKids Foundation, as well as SickKids job applicants, may also have been involved.
The hospital has not disclosed the number of people potentially affected or provided details of the specific categories of personal information involved.
Its review of the affected information remains on-going and SickKids said individuals confirmed as having been impacted will be notified directly.
UNITED KINGDOM
Rotherham Hospital and Community Charity has notified supporters of a cybersecurity incident involving Beacon CRM, a thirdparty platform used to manage supporter and donor information.
Beacon informed its customers that an unauthorised party had gained access to its systems and information stored within the platform may have been accessed.
The charity, which supports The Rotherham NHS Foundation Trust, said there is currently no evidence that personal information has been misused.
However, information held within Beacon may include names, postal addresses, email addresses, telephone numbers, donation and fundraising histories, communication records and emergency contact details.
The charity stressed that Beacon does not hold payment card details or bank account information on its behalf and said there is currently no indication that financial information has been compromised.
Rotherham Hospital and Community Charity is working with Beacon while the investigation continues. The incident has also been reported to the Information Commissioner’ s Office.
According to the charity, Beacon has introduced additional security measures and brought in specialist cybersecurity experts to assist with its response.
Supporters whose information may have been affected are being informed as a precaution and have been advised to remain alert for unexpected emails, messages and telephone calls.
WWW. INTELLIGENTCISO. COM 35