VYPR
breachPublished Sep 14, 2026· 1 source

Telus Warns Customers of Account Breaches Due to Stolen Credentials

Canadian telecom giant Telus is notifying customers of account breaches where threat actors used compromised credentials to access personal data and billing records.

Telus, one of Canada's largest telecommunications providers, has begun notifying a segment of its customer base about account breaches that have occurred over an extended period. The intrusions, which took place between February 2025 and June 2026, involved threat actors gaining unauthorized access to subscriber information.

The attackers leveraged compromised credentials to access Telus accounts, subsequently obtaining sensitive personal data. This included customer names, account numbers, phone numbers, billing addresses, email addresses, partial payment card numbers, subscription details, and payment history. The company has not explicitly stated the source of these compromised credentials, but the method suggests a credential stuffing attack or similar account takeover campaign.

Telus has indicated that the accessed account information has been used by the threat actors in attempts to persuade customers to switch their services to competing providers. In some instances, these unauthorized actions also led to modifications of the affected customers' services without their consent. The full extent of the breach, including the precise number of affected accounts, is still under investigation.

In response to the security incident, Telus has taken immediate steps to secure compromised accounts. This includes resetting the compromised credentials and implementing enhanced security monitoring for all affected accounts. The company has also notified the Vancouver Police Department about the breaches.

Customers impacted by the breaches are being offered complimentary identity theft protection services as a measure to mitigate potential harm. While Telus has not definitively confirmed the origin of the credentials, the nature of the attack strongly points towards the use of credentials obtained from third-party data leaks, a common tactic in large-scale account takeover operations.

This incident follows a separate breach involving Telus subsidiary Telus Digital in March, where the cybercrime group ShinyHunters claimed to have exfiltrated approximately 1 petabyte of data. While distinct from the current customer account breaches, it highlights ongoing security challenges for the company.

Telus has stated it is working to provide further details regarding the number of affected accounts and the specific source of the abused credentials. The ongoing investigation aims to fully understand the scope and impact of this significant data breach.

Synthesized by Vypr AI