www.securityweek.com 14 Sept 2026, 09:56 UTC

Telus Warns Canadian Customers of Account Takeovers and Data Theft

Telus Warns Canadian Customers of Account Takeovers and Data Theft
CyberSIXT Evidence Panel Source marked as original reporting

TELUS is notifying some Canadian consumer telecom customers that their accounts were breached and personal information accessed. The company said the intrusions occurred between February 2025 and June 2026, after an attacker used compromised credentials to enter accounts. Information potentially accessed included names, account numbers, telephone numbers, billing addresses, email addresses, partial payment card numbers, subscription details and payment histories.

Telus said the stolen account information was used in attempts to persuade customers to transfer their services to competitors, while some attackers made unauthorised changes to victims’ services. The number of affected accounts has not been disclosed. The company has reset compromised credentials, introduced enhanced monitoring for impacted accounts, notified the Vancouver Police Department and offered affected customers complimentary identity-theft protection.

The company’s description is consistent with credential stuffing or another account-takeover campaign, although Telus has not confirmed that the abused passwords came from a third party. SecurityWeek said it had asked Telus for clarification on the source of the credentials and the scale of the incident.

Telus subsidiary Telus Digital separately confirmed a breach in March after the ShinyHunters cybercrime group claimed to have stolen roughly 1 petabyte of data, but the article does not establish a link between that incident and the customer-account breaches.

View full article

Article by CyberSIXT