TELUS
Incident posture
Timeline
Summary
Telus warned customers that their accounts had been breached after attackers used compromised credentials to gain access to personal data including names, account numbers, phone numbers, billing addresses, email addresses, partial payment card numbers, subscription details and payment history. The stolen information was used to persuade some victims to switch service providers and to make unauthorized changes to their accounts. In response, the company reset the compromised credentials, added enhanced security monitoring to affected accounts, notified the Vancouver Police Department and offered complimentary identity theft protection services. The incident appears consistent with a credential stuffing or account takeover campaign, possibly leveraging credentials obtained from a third party, and follows a breach at its subsidiary that was claimed by the ShinyHunters group.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Telus, one of Canada’s largest telecommunications providers, began notifying customers in September 2026 that their consumer telecom accounts had been accessed without authorization. According to the breach notifications, the unauthorized access occurred between February 2025 and June 2026. The attacker used compromised credentials to log into accounts and viewed personal information stored therein, which included names, account numbers, phone numbers, billing addresses, email addresses, partial payment card numbers, subscription details, and payment history. The obtained data was subsequently used to try to persuade affected customers to switch their services to competing providers, and in certain instances the attacker made unauthorized modifications to the victims’ service configurations. Telus has not disclosed the exact number of accounts that were impacted, stating only that the figure remains unclear.
Upon discovering the breach, Telus reset the credentials that had been compromised and implemented enhanced security monitoring on the accounts that were affected. The company also notified the Vancouver Police Department about the incident and arranged for complimentary identity theft protection services to be offered to the victims whose data had been accessed. In its communications, Telus described the activity as consistent with a credential stuffing or other account‑takeover campaign that likely involved credentials obtained from a third party, although it has not confirmed that the abused passwords originated from such a source. The notification letters did not provide a specific count of affected accounts, nor did they detail the exact method by which the attacker obtained the compromised credentials.
Separately, in March 2026 Telus Digital, a subsidiary of Telus, confirmed that it had suffered a data breach after the ShinyHunters cybercrime group claimed to have exfiltrated approximately one petabyte of information from its systems. SecurityWeek has sought additional information from Telus regarding the total number of accounts affected in the consumer telecom breach and the precise origin of the credentials used in the attacks. As of the date of the notifications, Telus continued to monitor the impacted accounts and work with law enforcement to investigate the intrusion.
Sources
Sources available to members: 1 source.