news.mlab.sh
Back to the feed
data-breach

Telus Warns Customers of Account Breaches

Medium
Summary

Telus, a major Canadian telecom provider, has informed some customers of a data breach that exposed their personal information, including account details, payment information, and subscription history. The attackers exploited compromised credentials to gain access to accounts and attempted to lure customers to competitors, and the Vancouver Police Department has been notified. Telus has implemented security measures and offered identity theft protection to affected users.

Telus, one of Canada’s largest telecom providers, has notified some customers that their accounts have been breached and their personal information has been accessed. The breaches occurred between February 2025 and June 2026.

In data breach notifications sent to customers whose consumer telecom accounts were affected, Telus said the attackers used compromised credentials to access Telus accounts and the information they store, including names, account numbers, phone numbers, billing addresses, email addresses, partial payment card numbers, subscription details, and payment history. The attackers then used this information to attempt to convince customers to move their services to competitors, and in some cases, they made unauthorized changes to the victim’s services.

Telus has not yet released the exact number of affected accounts. The company stated it has reset the compromised credentials and added enhanced security monitoring to impacted accounts. The Vancouver Police Department has been notified, and victims have been offered complimentary identity theft protection services.

Telus’ brief description of the incident suggests the accounts were targeted in a credential stuffing or other account-takeover campaign involving credentials obtained from a third party. However, the company has not said specifically that the abused passwords came from a third party.

In March, Telus Digital, a subsidiary of Telus, confirmed suffering a data breach after the notorious ShinyHunters cybercrime group claimed to have stolen roughly 1 petabyte of information from the company’s systems.

SecurityWeek has reached out to Telus for additional information, including the number of affected accounts and clarification on the source of the credentials the attacker abused.

Read the full article at SecurityWeek