Telus Issues Security Alert: Customer Accounts Compromised
Telus has informed certain customers that their accounts have been compromised, with personal data accessed by unauthorized parties.
Details of the Breach
Timeline and Scope
The telecom provider disclosed that the breaches occurred between February 2025 and June 2026, during which attackers utilized stolen credentials to gain entry to consumer accounts.
Compromised Data
The compromised data includes names, account numbers, phone numbers, billing addresses, residential addresses, partial payment card details, subscription information, and payment records.
Actions Taken by Telus
The intruders leveraged this information to contact victims, attempting to persuade them to switch services to competitors, and in some instances, made unauthorized modifications to affected accounts. Telus has since reset the compromised credentials and implemented enhanced security monitoring for affected users.
Subsidiary Breach
Earlier in March, a subsidiary of Telus, Telus Digital, reported a separate data breach following claims by the ShinyHunters cybercriminal group that they exfiltrated approximately 1 petabyte of data from its systems.
Ongoing Investigations
Local law enforcement, specifically the Vancouver Police Department, has been notified, and affected individuals are being provided with complimentary identity theft protection services. The company’s statement indicates the breach likely involved a credential stuffing attack or similar account takeover method, though it did not confirm whether the stolen credentials originated from a third-party source.
Call for Transparency
SecurityWeek has sought further details from Telus, including the total number of affected accounts and clarification on the source of the credentials used in the attack.
