Telus, a leading telecommunications firm in Canada, has alerted some of its customers about a security breach involving unauthorized access to their accounts and personal data.
Incident Overview
Notifications were dispatched to affected customers, revealing that breaches occurred from February 2025 to June 2026. The company reported that the security breach involved compromised credentials, granting attackers access to sensitive information such as customer names, account numbers, phone numbers, billing and email addresses, alongside partial payment card numbers, subscription data, and payment records.
Misuse of the accessed data has led to attempts to persuade customers to switch their services to rival providers, with some accounts experiencing unauthorized modifications.
Response and Security Measures
The precise number of impacted accounts remains unspecified. However, Telus has taken steps to mitigate the situation by resetting compromised credentials and enhancing security monitoring on affected accounts. In addition, the Vancouver Police Department has been informed, and those impacted have been offered complimentary identity theft protection services.
The brief details shared by Telus indicate that the incident might be part of a credential stuffing or account-takeover scheme, potentially involving credentials obtained from third-party sources. Nonetheless, the company has not confirmed that the compromised passwords originated from external databases.
Additional Context and Implications
In a related incident, Telus Digital, a subsidiary of Telus, disclosed in March that it suffered a data breach when the notorious cybercrime group ShinyHunters claimed responsibility for stealing about 1 petabyte of data from their systems.
SecurityWeek has contacted Telus seeking further information, including the total number of affected accounts and details regarding the origin of the compromised credentials.
Such breaches highlight the ongoing challenges in cybersecurity, urging companies and customers alike to remain vigilant and adopt robust security practices.
Related articles discuss recent security incidents involving other companies, underscoring the pervasive threat of cyberattacks in today’s digital landscape.
