Breaking
Cyber CrimeDeveloping Story

Telus Alerts Users to Account Takeovers

Canadian telecom giant Telus is notifying customers that their accounts were breached and personal data accessed, though the scope remains unclear.

··2 hours ago·7 min read
black and white smartphone on persons hand
Photo by Tech Daily on Unsplash

Telus, one of Canada's largest telecom providers, is quietly notifying a set of its customers that their consumer accounts were broken into and their personal information was accessed. The company's notification describes intrusions that unfolded over a span the company dates from February 2025 to June 2026 — a window that, on the company's own dates, is still open at the far end. What Telus has not said is how many accounts were caught up in it.

The warning lands in a year already marked by breach disclosures at the company and its subsidiaries, and it puts a specific kind of harm in front of customers: not just data exposure, but active attempts to peel them away from Telus's services.

Credentials Opened the Door

According to Telus's notices, the attacker gained entry using compromised credentials — username-and-password pairs that let them authenticate as the account holder. From there, they reached the information those accounts store. Telus lists the exposed data as names, account numbers, phone numbers, billing addresses, email addresses, partial payment card numbers, subscription details, and payment history.

That set is broader than a simple login leak. It spans contact details, identifiers tied to a specific account, and fragments of billing information. Telus says the obtained account information was then used in attempts to convince customers to move their services to competitors, and that in some cases the attackers made unauthorized changes to the victim's services.

The company's description stops short of naming the source of the passwords. As SecurityWeek reported, Telus's account of the incident is consistent with a credential-stuffing or broader account-takeover campaign drawing on credentials obtained from a third party — but the company has not said specifically that the abused passwords came from a third party. That distinction matters, because it separates a Telus-specific compromise from the reuse of passwords that leaked somewhere else entirely.

SecurityWeek said it reached out to Telus for additional information, including the number of affected accounts and clarification on where the abused credentials originated.

What Telus Has Done So Far

In response, Telus said it has reset the compromised credentials and added enhanced security monitoring to the impacted accounts. The Vancouver Police Department has been notified, and victims have been offered complimentary identity theft protection services.

Those are the concrete measures the company has confirmed. A credential reset forces a new password; enhanced monitoring watches the account for further suspicious activity; the identity theft protection offer is aimed at the downstream risk that exposed personal data can be used to open accounts or impersonate the victim elsewhere.

Whether those steps are sufficient depends heavily on questions Telus has not answered — chiefly how many accounts were touched and whether the reused passwords originated inside or outside the company's systems.

An Open-Ended Breach Window

The dates in the notification are worth reading closely. Telus dates the intrusions from February 2025 to June 2026. The company has not explained why the activity appears to run to that endpoint, nor whether the intrusions have stopped.

An open-ended window of that kind is unusual to see stated plainly in a customer notice. It also means the incident is not neatly bracketed: the company is describing a period of account access rather than a single, contained event with a clear start and finish.

Telus has not attached a count to the notification. Without a figure, customers have no way to gauge whether the activity was a narrow, targeted effort or something wider.

The Telus Digital Breach in March

The new notifications are not the first breach trouble for the Telus corporate family this year. In March, subsidiary Telus Digital confirmed suffering a data breach after the ShinyHunters cybercrime group claimed to have stolen roughly 1 petabyte of information from the company's systems.

That episode put Telus in the headlines alongside a group known for high-volume data theft. The current consumer-account notifications are a separate matter on their face — Telus frames them around credential abuse against customer accounts rather than a wholesale exfiltration from corporate systems.

Still, the two disclosures sit close together in time, and both involve Telus data. SecurityWeek's report notes the company has not connected them, and no evidence in the notifications links the consumer account intrusions to the earlier Telus Digital incident.

Why Competitor Poaching Is the Strange Part

Most breach notices describe risk in the abstract — data exposed, fraud possible. Telus's notice describes something more specific: the attacker used the account information to try to talk customers into switching providers, and in some cases altered their services outright.

That turns a data theft into an active manipulation campaign. A caller who knows your name, your account number, your billing address, and details of your subscription can sound convincingly like a representative of your provider. The unauthorized service changes add a second layer — they are actions taken against the account, not just information read from it.

Telus has not described the mechanics of those calls or changes in further detail, nor said which competitors, if any, were named in the attempts.

Where the Facts Stand

Here is what Telus has confirmed, according to its notifications and SecurityWeek's reporting:

  • The intrusions occurred between February 2025 and June 2026, per Telus.
  • Exposed data includes names, account numbers, phone numbers, billing addresses, email addresses, partial payment card numbers, subscription details, and payment history.
  • Account information was used to try to convince customers to move to competitors, with unauthorized service changes in some cases.
  • Telus reset compromised credentials and added enhanced security monitoring to impacted accounts.
  • The Vancouver Police Department has been notified.
  • Victims were offered complimentary identity theft protection services.
  • Telus has not disclosed how many accounts were affected.
  • In March, subsidiary Telus Digital confirmed a breach after ShinyHunters claimed roughly 1 petabyte of stolen data.

The company has not said whether the credentials it reset were reused across other services, nor identified a third-party source for the passwords.

What Customers Can Act On

For anyone who received a Telus notification, the company's own steps give a starting point. The credential reset means any password the customer was using for their Telus account should be treated as no longer valid — and if that same password was used anywhere else, it should be changed there too. The offer of identity theft protection services is available to affected customers, and the Vancouver Police Department has been brought into the matter.

Customers should also watch for contact that references the specific data Telus says was exposed. A caller who already knows the account number, billing address, and subscription details is not proof of legitimacy — that information is exactly what the breach put in circulation, per the company's notice.

Telus has not published a customer-facing list of additional steps beyond the credential reset, monitoring, and identity protection offer. SecurityWeek's requests for the number of affected accounts and the source of the credentials were still pending at the time of its report.

The Unanswered Question

The central gap in the Telus notification is scale. A breach with no account count attached leaves customers unable to tell whether they were among a handful of targets or part of something much larger. The same absence makes it hard for anyone outside the company to assess how the intrusions were carried out.

Telus's brief description points toward credential stuffing or another account-takeover pattern involving credentials obtained from a third party — but the company has not stated that the abused passwords came from a third party. That single clarification would change how customers should read the incident: a third-party credential source points to password reuse across services, while an internal source points back at Telus's own systems.

For now, the notification describes what happened, what data was involved, and what Telus has done. The questions of how many and how the credentials were obtained remain open.

Why This Matters Beyond One Carrier

The Telus case is a reminder of how much a phone account can unlock. The data Telus says was exposed — account numbers, billing addresses, partial card numbers, payment history — is the kind of material that helps an attacker sound credible on a support call or in a message to a customer. That is precisely what Telus says happened here, with attempts to move customers to competitors and unauthorized changes to their services.

For other telecom customers, the practical lesson is that account security is not only about the password on the account. If reused credentials were the entry point, as the incident description suggests, then a leak at one service can become a foothold at another. The countermeasure is the unglamorous one: unique passwords per account, and treating unexpected calls or messages about your service with suspicion even when the caller knows your details.

For providers, the notice is a reminder that a credential reset and monitoring are the floor, not the ceiling. When an attacker can use stolen account data to impersonate a company to its own customers, the response has to account for the customer-facing consequences too. Telus has not yet said how widely that consequence was felt — and until it does, the full picture of this incident stays out of view.

#telus#data breach#account takeover#credential stuffing#telecom security

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories