Telus, one of Canada’s largest telecom providers, has begun notifying customers that their accounts were breached by an attacker using compromised login credentials. The company said the intrusions took place between February 2025 and June 2026, though it has not disclosed how many accounts were affected.
According to breach notifications sent to impacted consumer telecom customers, the attacker accessed account information including names, account numbers, phone numbers, billing addresses, email addresses, partial payment card numbers, subscription details, and payment history.
Attackers Tried to Poach Customers
Telus said the stolen account data was used in an unusual way: attackers leveraged the information to try to convince customers to switch their telecom services to competing providers. In some instances, the attackers went further and made unauthorized changes directly to victims’ service plans.
The company has not explicitly confirmed the source of the compromised credentials, but the pattern described, unauthorized logins using valid usernames and passwords, is consistent with a credential stuffing or account takeover campaign relying on credentials obtained from a third party rather than a direct breach of Telus systems.
Response and Remediation
Telus said it has reset the compromised credentials tied to affected accounts and added enhanced security monitoring to detect further suspicious activity. The Vancouver Police Department has been notified of the incident, and affected customers are being offered complimentary identity theft protection services.
Second Incident This Year
This is not the only security issue Telus has faced recently. In March, its subsidiary Telus Digital confirmed a separate data breach after the ShinyHunters cybercrime group claimed to have stolen roughly one petabyte of data from the subsidiary’s systems. It is not clear whether the two incidents are related.
Telus has not yet responded to requests for additional details, including the total number of accounts affected by the account takeover campaign or clarification on where the abused credentials originated.
What Customers Should Do
- Change passwords on Telus accounts and any other accounts reusing the same credentials
- Enable multi-factor authentication where available
- Watch for unsolicited offers or unauthorized changes to service plans
- Monitor billing statements and credit reports for suspicious activity
