CSIDB logo
Incident

TELUS

Incident posture

Attack window
Feb 2025
Location
Canada
Status
Unknown
CIA posture
Available to members
Updated
2026-09-24 03:05

Linked entities

Victim
TELUS
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Telus warned customers that some accounts had been breached, with attackers using compromised credentials to access names, account numbers, phone numbers, billing addresses, email addresses, payment card numbers, subscription details and payment history. The data was used to lure victims to rival services and to make unauthorized changes to their accounts. The company reset the compromised credentials, added security monitoring, notified police and offered identity theft protection, while noting the incident resembled a credential‑stuffing campaign and that a subsidiary had previously reported a breach claimed by a known cybercrime group.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

Telus began notifying customers in September 2026 that their consumer telecom accounts had been accessed without authorization between February 2025 and June 2026. The intruder used compromised credentials to log into accounts and view personal data such as names, account numbers, phone numbers, billing addresses, email addresses, partial payment card numbers, subscription details and payment history. The stolen information was subsequently used to try to persuade affected customers to switch their services to competing providers and, in some instances, to make unauthorized changes to the victims’ service configurations. Telus has not disclosed the exact number of accounts that were impacted by the breach.

In response, Telus reset the credentials that had been compromised and implemented enhanced security monitoring on the affected accounts. The company also notified the Vancouver Police Department of the incident and offered complimentary identity‑theft protection services to the customers whose data was exposed. Telus described the activity as consistent with a credential‑stuffing or account‑takeover campaign involving credentials obtained from a third party, although it has not confirmed that the abused passwords originated outside its own systems. The breach follows a separate incident in March 2026 in which Telus Digital, a subsidiary, reported a data breach after the ShinyHunters group claimed to have exfiltrated approximately one petabyte of information from its systems.

SecurityWeek has sought further details from Telus, including the total number of affected accounts and clarification on the source of the credentials used in the attacks, but the company has not yet provided those specifics. As of the date of the notification, no additional technical details about the attack vectors or the duration of the unauthorized access beyond the stated window have been made public. The notifications to customers remain the primary public communication from Telus regarding this incident.

Sources

Sources available to members: 1 source.

CSIDB