Telus, a prominent Canadian telecom company, has begun notifying customers that their accounts were breached. The company stated that these intrusions took place over an extended period, specifically between February 2025 and June 2026.
Attackers gained access to Telus accounts using compromised credentials. The accessed information includes names, account numbers, phone numbers, billing addresses, email addresses, partial payment card numbers, subscription details, and payment history. Telus suggests the method involved credential stuffing or similar account takeover tactics, though the source of the compromised credentials has not been explicitly stated.
The stolen account information was subsequently used by attackers to attempt to persuade customers to transfer their services to competing providers. In some instances, unauthorized modifications were made to the victims' services.
In response to the breaches, Telus has reset the compromised credentials for affected accounts and implemented enhanced security monitoring. The company has also reported the incidents to the Vancouver Police Department and is offering complimentary identity theft protection services to the impacted customers. The total number of affected accounts remains undisclosed.
This incident follows a separate data breach confirmed in March by Telus Digital, a subsidiary, where the ShinyHunters cybercrime group claimed to have exfiltrated a significant volume of data. The current notification pertains specifically to consumer telecom accounts.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Telus, a major Canadian telecom provider, is informing customers about account breaches that occurred between February 2025 and June 2026. Attackers used compromised credentials to access personal information and make unauthorized service changes, with some data used to solicit customers to switch providers.