Menu
Browse

Cyber Incident Victim: Hospital for Sick Children

Date:

Dec 2022

Location:

Canada

Summary

A ransomware attack targeted a Toronto-based children's hospital, disrupting internal systems, corporate networks, phone lines, and its website. The incident caused operational delays in laboratory and imaging result processing, extended patient wait times, and affected diagnostic and treatment systems. The LockBit ransomware operation claimed responsibility, acknowledging that an affiliate violated its policies prohibiting attacks on medical institutions where such incidents could endanger lives. The group subsequently provided a free decryptor and apologized for the breach of its rules, which permit data theft from healthcare organizations but restrict encryption of critical medical facilities. The hospital restored half of its priority systems within days of the attack while managing ongoing system recovery efforts under a declared internal emergency status. LockBit operates under a ransomware-as-a-service model, where affiliates conduct attacks and share ransom proceeds with the operators.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On December 18, 2022, the Hospital for Sick Children (SickKids) in Toronto experienced a ransomware attack that disrupted multiple network systems. The hospital declared a Code Grey—indicating a system failure—as the incident affected internal and corporate systems, hospital phone lines, and its public website. SickKids publicly confirmed the cybersecurity event via a social media statement on the same day, asserting that patient care remained unaffected at the initial stage. The attack encrypted a limited number of systems but caused operational delays, particularly in receiving laboratory and imaging results, which extended patient wait times. Diagnostic and treatment workflows were impacted, though the hospital did not specify the duration of these disruptions.

Cyber Incident Image

By December 29, 2022, SickKids had restored 50% of its priority systems, focusing on those directly linked to diagnostic or treatment delays. The LockBit ransomware gang claimed responsibility for the attack but later issued a public apology and provided a free decryptor to the hospital. LockBit stated that one of its affiliates violated its operational policies, which prohibit encrypting systems at medical institutions where attacks could risk patient fatalities, such as hospitals performing computer-assisted surgical procedures. The gang permits data theft from medical entities but restricts encryption attacks on specific high-risk facilities. LockBit operates under a Ransomware-as-a-Service model, where affiliates conduct attacks and share ransom payments with the operators, who retain approximately 20% of proceeds. This incident followed a precedent set in May 2021, when the Conti ransomware group provided Ireland’s Health Service Executive (HSE) with a free decryptor amid law enforcement pressure.

Sources
Sources available to members
2 sources