TELUS
Incident posture
Timeline
Summary
Telus warned customers that some accounts had been breached, with attackers using compromised credentials to access names, account numbers, phone numbers, billing addresses, email addresses, payment card numbers, subscription details and payment history. The data was used to lure victims to rival services and to make unauthorized changes to their accounts. The company reset the compromised credentials, added security monitoring, notified police and offered identity theft protection, while noting the incident resembled a credential‑stuffing campaign and that a subsidiary had previously reported a breach claimed by a known cybercrime group.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Telus began notifying customers in September 2026 that their consumer telecom accounts had been accessed without authorization between February 2025 and June 2026. The intruder used compromised credentials to log into accounts and view personal data such as names, account numbers, phone numbers, billing addresses, email addresses, partial payment card numbers, subscription details and payment history. The stolen information was subsequently used to try to persuade affected customers to switch their services to competing providers and, in some instances, to make unauthorized changes to the victims’ service configurations. Telus has not disclosed the exact number of accounts that were impacted by the breach.
In response, Telus reset the credentials that had been compromised and implemented enhanced security monitoring on the affected accounts. The company also notified the Vancouver Police Department of the incident and offered complimentary identity‑theft protection services to the customers whose data was exposed. Telus described the activity as consistent with a credential‑stuffing or account‑takeover campaign involving credentials obtained from a third party, although it has not confirmed that the abused passwords originated outside its own systems. The breach follows a separate incident in March 2026 in which Telus Digital, a subsidiary, reported a data breach after the ShinyHunters group claimed to have exfiltrated approximately one petabyte of information from its systems.
SecurityWeek has sought further details from Telus, including the total number of affected accounts and clarification on the source of the credentials used in the attacks, but the company has not yet provided those specifics. As of the date of the notification, no additional technical details about the attack vectors or the duration of the unauthorized access beyond the stated window have been made public. The notifications to customers remain the primary public communication from Telus regarding this incident.
Sources
Sources available to members: 1 source.