Telus Warns Customers of Account Breach Exposing Personal Data
Telus, one of Canada's largest telecommunications providers, has begun notifying an undisclosed number of consumer telecom customers that their accounts were compromised between February 2025 and June 2026. The company confirmed that attackers gained access to accounts using compromised credentials, suggesting a credential stuffing or account takeover campaign leveraging usernames and passwords likely harvested from third-party sources. The pattern is consistent with widely reported account takeover tactics, where attackers automate login attempts using leaked credentials obtained from unrelated data breaches. Users can verify whether their email addresses have appeared in known breaches using a breach checker and test the strength of their current passwords with a password checker.
The accessed data set is broad and includes full names, account numbers, phone numbers, billing addresses, email addresses, partial payment card numbers, subscription details, and payment history. Telus reported that the attackers did not stop at data theft: they used the stolen account information to impersonate representatives and convince affected customers to migrate their services to competing carriers, and in some cases made unauthorized changes to victim accounts. This dual-purpose attack combining data harvesting with active service manipulation highlights the operational sophistication of modern account takeover operations and underscores the importance of securing customer-facing portals with multi-factor authentication.
In response, Telus has reset the compromised credentials, deployed enhanced security monitoring on affected accounts, notified the Vancouver Police Department, and offered complimentary identity theft protection services to victims. The incident follows a separate March disclosure from Telus subsidiary Telus Digital, which confirmed a major breach after the ShinyHunters cybercrime group claimed to have exfiltrated roughly 1 petabyte of data from the company's systems. SecurityWeek has reached out to Telus for clarification on the total number of impacted accounts and whether the abused credentials originated from a third-party source.
Affected customers are advised to change passwords across any account sharing the same login, enable two-factor authentication where available, monitor financial statements for suspicious activity, and review their overall digital exposure. A comprehensive privacy checkup can help users identify where their personal data may be publicly accessible. Until Telus discloses more details, the breach serves as another reminder that single-factor authentication on telecom accounts remains a high-value target for financially motivated threat actors seeking both data and revenue through fraudulent service transfers.