Telus Issues Security Alert: Customer Accounts Compromised

www.news4hackers.com-telus-issues-security-alert-customer-accounts-compromised-telus-issues-security-alert-customer-accounts-compromised

Telus has informed certain customers that their accounts have been compromised, with personal data accessed by unauthorized parties.

Details of the Breach

Timeline and Scope

The telecom provider disclosed that the breaches occurred between February 2025 and June 2026, during which attackers utilized stolen credentials to gain entry to consumer accounts.

Compromised Data

The compromised data includes names, account numbers, phone numbers, billing addresses, residential addresses, partial payment card details, subscription information, and payment records.

Actions Taken by Telus

The intruders leveraged this information to contact victims, attempting to persuade them to switch services to competitors, and in some instances, made unauthorized modifications to affected accounts. Telus has since reset the compromised credentials and implemented enhanced security monitoring for affected users.

Subsidiary Breach

Earlier in March, a subsidiary of Telus, Telus Digital, reported a separate data breach following claims by the ShinyHunters cybercriminal group that they exfiltrated approximately 1 petabyte of data from its systems.

Ongoing Investigations

Local law enforcement, specifically the Vancouver Police Department, has been notified, and affected individuals are being provided with complimentary identity theft protection services. The company’s statement indicates the breach likely involved a credential stuffing attack or similar account takeover method, though it did not confirm whether the stolen credentials originated from a third-party source.

Call for Transparency

SecurityWeek has sought further details from Telus, including the total number of affected accounts and clarification on the source of the credentials used in the attack.



About Author

en_USEnglish