
Telus, one of Canada’s largest telecom providers, is notifying some customers that their accounts have been breached and their personal information has been accessed.
In data breach notifications sent to customers whose consumer telecom accounts were affected, Telus said the intrusions occurred between February 2025 and June 2026.
According to the company, the attacker used compromised credentials to access Telus accounts and the information they store, including names, account numbers, phone numbers, billing addresses, email addresses, partial payment card numbers, subscription details, and payment history.
Telus said the obtained account information has been used to attempt to convince customers to move their services to competitors, and in some cases the attackers made unauthorized changes to the victim’s services.
It’s unclear how many accounts the breach affected.
Telus said it has reset the compromised credentials and added enhanced security monitoring to impacted accounts. The Vancouver Police Department has been notified, and victims have been offered complimentary identity theft protection services.
Telus’ brief description of the incident suggests the accounts were targeted in a credential stuffing or other account-takeover campaign involving credentials obtained from a third party. However, the company has not said specifically that the abused passwords came from a third party.
In March, subsidiary Telus Digital confirmed suffering a data breach after the notorious ShinyHunters cybercrime group claimed to have stolen roughly 1 petabyte of information from the company’s systems.
SecurityWeek has reached out to Telus for additional information, including the number of affected accounts and clarification on the source of the credentials the attacker abused.
Related: Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

