TELUS has started notifying customers that unauthorized individuals used compromised credentials to get into consumer telecom accounts, in an intrusion window the company places between February 2025 and June 2026. That is roughly sixteen months of access before anyone shut it down. The notification letters began arriving in the second week of September 2026, and they list exposed personal and billing data, confirm that some customers had their services changed without permission, and describe a monetization angle you do not see often in breach disclosures: the attackers allegedly used stolen account details to contact customers directly and talk them into moving their services to competitors.
If you are thinking of the March 2026 incident, this is a different one. That was TELUS Digital confirming that the ShinyHunters extortion group had claimed close to a petabyte of data from its business-process-outsourcing operations. Everything known so far about this incident, including the access method, the data scope and the motive, points to a separate and much slower operation: a prolonged account-takeover campaign against live customer accounts rather than a smash-and-grab on cloud infrastructure. What follows is a breakdown of what happened, how this class of attack works, how the two TELUS incidents differ, and what affected customers should do next.
What happened, according to TELUS
In an email to Daily Hive, a TELUS spokesperson said the company had recently found and blocked unauthorized access to limited information held in a “small number” of consumer telecom accounts. The customer letters are more specific about the mechanics. They say unauthorized individuals used compromised credentials to access the customer’s TELUS account at some point between February 2025 and June 2026, and that those credentials have since been terminated.

The data list is not the part that should worry you. What the attackers allegedly did with it is. The letter says those individuals may have used the customer’s account information to “persuade you to move your services away from TELUS towards competitors”, and may have made unauthorized changes to their TELUS services. TELUS director of public affairs Richard Gilhooley told CTV News that affected customers were notified and given complimentary identity protection, and that the company contacted both law enforcement and the Privacy Commissioner of Canada. SecurityWeek reports that TELUS also reset the compromised credentials and added enhanced security monitoring to impacted accounts, with the Vancouver Police Department now investigating.
TELUS has not said how many accounts were affected, nor where the compromised credentials came from. The credential source is the question that decides whether this was credential stuffing against a login page, abuse of harvested session tokens, or something closer to an insider or partner-channel problem, so the silence has consequences for anyone trying to learn from it.
What information was exposed, and why each field matters
The notification lists the accessed data as: full name, account number, billing address, preferred language, phone number or numbers and, in most cases, email address; the last four digits of the payment card on file; and the type of services subscribed to, along with the amounts charged and payment history for those services.
Individually, none of these fields is a password or a full card number. Together they are a working social-engineering kit, which is why the “no full card numbers” framing undersells the risk here.
| Exposed data element | Why it has value in an attacker’s hands |
|---|---|
| Full name and billing address | Anchors any pretext, and passes knowledge-based verification at banks, utilities and other carriers |
| TELUS account number | Lets a fraudster pose as you when calling support, since account numbers are routinely used as an identity check |
| Phone numbers | The starting point for targeted vishing calls and for SIM-swap or port-out attempts against your number |
| Email address | Feeds phishing lists and password-reset attempts on your other services |
| Preferred language | Lets scam calls and emails arrive in the language you are most likely to trust |
| Last four digits of payment card | Makes fraudulent contact feel legitimate: “we see the Visa ending in 4321 on your account” |
| Service types, charges, payment history | Reveals exactly what you pay and for what, letting a poacher pitch a precise better deal and time it to your billing cycle |
Payment history is the underrated item. Knowing what a customer pays each month, and whether they pay on time, tells a fraudulent retention agent or competitor broker exactly how aggressive a discount offer needs to be. It also tells a phisher which invoices will look believable.
The unusual motive: poaching subscribers with stolen data
Breach monetization usually follows familiar paths: extortion, card fraud, identity theft, resale on dark-web markets. This notification describes something closer to the telecom industry’s oldest fraud, slamming, which is switching or attempting to switch a customer’s service without genuine consent, upgraded with real account intelligence. Someone who knows your name, your bill, your card’s last four digits and your service bundle can call you sounding exactly like a legitimate sales or retention rep, because they hold the same facts a legitimate rep would.
That is why the letter explicitly warns customers to be cautious of unsolicited calls about service offers and of door-to-door representatives, and tells anyone who spots unexpected changes on their account or recent bills to contact the company immediately. Whether the actors here were rogue sales-channel agents, a competitor-adjacent broker network, or cybercriminals selling warm leads built from stolen account data is not public. What is clear is that the breached data got operationalized as a persuasion tool, which leaves every affected customer a live target for follow-on vishing and in-person scams for months after the intrusion ended.
📬 Stay Ahead of Cyber Threats
Get the latest cybersecurity news, critical vulnerabilities, threat intelligence, tutorials, and exclusive giveaways delivered straight to your inbox. No spam. Unsubscribe anytime.
Subscribe to the Newsletter →How a credential attack survives for sixteen months
For readers new to the terminology: compromised credentials means usernames and passwords, or session tokens, that were already in an attacker’s possession before they touched TELUS. Those credentials usually come from password reuse after an unrelated third-party breach, from infostealer malware logs harvested off infected PCs and phones, or from phishing. Once acquired, attackers validate them at scale against login pages and APIs in what is called credential stuffing, generally through botnets and residential proxy networks so that each individual login attempt looks like an ordinary customer signing in from home.
That is also why the dwell time ran so long. A successful credential-stuffing login does not look like a hack to most monitoring systems. It looks like a correct password. Without strong signals such as impossible-travel detection, device-fingerprint anomalies, velocity checks and step-up authentication on sensitive views, an attacker sitting inside a customer account portal is indistinguishable from the customer. Industry guidance such as NIST SP 800-63B pushes operators to screen passwords against known-breach corpora and to require phishing-resistant multi-factor authentication, but MFA coverage on telecom self-care portals, legacy APIs and partner channels has historically been uneven, and OTP-based MFA can be defeated by the same social engineering this breach describes.
SecurityWeek reads the notification language as suggesting credential stuffing or another account-takeover campaign using credentials obtained from a third party, while noting that TELUS has not confirmed the source. Our reading agrees, with one addition. The combination of long dwell time, selective targeting of consumer telecom accounts, and commercial exploitation through poaching rather than extortion fits a low-and-slow, human-operated campaign recycling validated credentials better than it fits a noisy automated stuffing burst, which defenders usually catch within days. Either way the defensive lesson is the same: credentials stolen elsewhere are weapons aimed at every service where the victim reused them, and detection engineering for account takeover has to assume the password will be correct.
Worth stating plainly, too, is why telecom accounts are prized beyond the billing data. Your phone number is the recovery channel for your banking, email and crypto accounts. An attacker with control of, or insight into, a carrier account is one step from intercepting one-time passwords or attempting a SIM swap or port-out. That is why regulators including the FCC have imposed specific SIM-swap and port-out fraud rules on carriers, and why any breach touching carrier account data deserves more concern than its field list implies.
Not ShinyHunters: keeping the two TELUS incidents straight
People are mixing this incident up with the March 2026 TELUS Digital breach, and the two really are separate events. As BleepingComputer reported, ShinyHunters breached TELUS Digital using Google Cloud Platform credentials found in data stolen during the Salesloft Drift compromise, the campaign Google’s threat-intelligence team tracks as UNC6395, in which attackers drained Salesforce data from hundreds of companies and mined support tickets for tokens and secrets. Google’s GTIG advisory covers that campaign in detail. From there the group reached a large BigQuery instance, used the secret-scanning tool TruffleHog to find further credentials, and claimed close to a petabyte of stolen data including call records, voice recordings and source code, before demanding $65 million. TELUS did not pay.
Consumer account intrusion (this incident) TELUS Digital intrusion (March 2026) Target TELUS consumer telecom customer accounts TELUS Digital BPO systems and cloud environment Window Feb 2025 to Jun 2026, disclosed Sept 2026 Multi-month, confirmed Mar 12, 2026 Initial access Compromised customer or account credentials, source unconfirmed GCP credentials leaked via Salesloft Drift breach Attributed actor Unattributed ShinyHunters Data Customer PII, billing and payment history About 1 PB claimed: BPO client data, call records, recordings, code Monetization Subscriber poaching, unauthorized service changes $65M extortion attempt, rejected Response Credentials terminated, VPD and OPC engaged Forensics firms engaged, law enforcement involved
There is a historical echo here for long-time observers. TELUS-owned Koodo Mobile’s 2020 breach notification used nearly identical language, with an unauthorized third party using compromised credentials to access systems and copy customer data that later surfaced for sale. Six years apart, credential-based access to Canadian telecom customer data has repeated itself, which argues for structural fixes over one-off cleanups.
TELUS’s response, measured against what good looks like
On containment, TELUS did the fundamentals. It terminated the compromised credentials, added enhanced monitoring to impacted accounts, notified affected customers, and engaged both police and the privacy regulator. Notification to the Privacy Commissioner of Canada is consistent with PIPEDA’s mandatory breach-reporting regime, which requires organizations to report breaches posing a real risk of significant harm, notify affected individuals, and keep records of every breach. It also gives Canadian customers a regulatory path if they think the response falls short.
On remediation, the offer is comparatively generous: two years of complimentary Telus Guardian identity theft protection provided through Norton, with enrolment open until November 30, 2026. Per the notification, the membership includes identity theft and dark-web monitoring, one-bureau credit monitoring, an annual credit report and score, reimbursement of up to $25,000 for stolen funds, up to $25,000 for personal expenses incurred during restoration, up to $1 million in coverage for lawyers and experts, access to an identity restoration team, and a free 90-day subscription to Norton Security Deluxe.
The gaps are transparency gaps. No account count, no credential-source explanation, and a sixteen-month window expressed as a range all leave customers and researchers guessing about real exposure. A “small number of accounts” is not auditable, and until TELUS clarifies whether the credentials were customer-reused passwords, harvested session tokens or something internal, defenders elsewhere cannot fully learn from the incident.
If you’re a TELUS customer: what to do this week
The notification is where your response starts. Work through the following in order.
- Verify the email. Do not click links or call numbers inside the email. Log in by typing telus.com directly, or call the number printed on your bill, and ask whether your account was in the notified population. TELUS says it is inviting notified customers to contact the company if they have doubts about the letter’s authenticity, which is a quiet acknowledgement that breach-themed phishing will follow this disclosure.
- Audit your account for changes. Review current services, the contact email on file, call-forwarding settings, recent bills and one-time charges. The notification specifically asks customers who see unexpected changes to their account or bills to contact TELUS immediately. Document anything you find with screenshots and dates.
- Rotate credentials and harden authentication. Set a new, unique password for your TELUS account and anywhere you reused the old one, enable multi-factor authentication with an app or hardware key rather than SMS where you have the choice, and add an account PIN or port-out lock so your number cannot be moved or your SIM swapped on a phone call alone.
- Enrol in the free protection before November 30, 2026. Two years of Telus Guardian via Norton costs you nothing and adds dark-web and credit monitoring plus meaningful insurance limits. For belt and braces, also place a free credit freeze with Equifax and TransUnion Canada, which blocks new-account fraud regardless of this breach.
- Assume you will be contacted by people quoting your real data. Credibility is the entire point of the stolen dataset. Hang up on unsolicited retention or switching offers and call back through official channels, never read out one-time codes, and treat door-to-door salespeople claiming TELUS affiliation with the same suspicion. Report suspected fraud attempts to the Canadian Anti-Fraud Centre.
- Watch for the second wave. Expect phishing emails and smishing texts referencing the breach, your name, your bill amount or your card’s last four digits over the coming months. Those details prove the sender has stolen data. They do not prove the sender is TELUS.
What security teams should take from this incident
For practitioners, the TELUS consumer-account intrusion is a clean case study in a few persistent blind spots.
Account-takeover detection cannot lean on authentication failure signals. When the password is correct, you need behavioral analytics, device intelligence and step-up checks on high-value views such as billing history and service changes.
Credential hygiene is a third-party risk problem. Every breach anywhere else becomes an attack vector on your login page, which makes breached-password screening and phishing-resistant MFA baseline controls rather than upgrades.
The monetization pattern, stolen data used to socially engineer customers in real time, means breach impact assessments have to model follow-on fraud against customers, not only regulatory exposure from the exfiltrated fields. Sixteen months of dwell time in a customer-facing portal is a detection-engineering failure that carriers, banks and SaaS operators should be red-teaming against their own portals now.
Frequently asked questions
How do I know if my TELUS account was affected?
TELUS is notifying affected customers directly by email. If you did not receive a notification, your account was presumably not in the impacted population, but you can confirm by contacting TELUS through official channels, meaning the number on your bill or the logged-in support portal, rather than through any link in an email.
Were full credit card numbers or passwords stolen?
No. The notification states that only the last four digits of the payment card on file were accessed, and it does not list passwords or full card numbers among the exposed data. The greater practical risk is social engineering built from the exposed billing and contact details.
Is this the same breach as the ShinyHunters / TELUS Digital incident?
No. The ShinyHunters incident, confirmed in March 2026, hit TELUS Digital’s cloud and BPO environments via credentials leaked in the Salesloft Drift compromise and resulted in an extortion demand. This incident involves unauthorized access to consumer telecom customer accounts using compromised credentials over a February 2025 to June 2026 window.
How long did the breach last before TELUS stopped it?
TELUS places the unauthorized access between February 2025 and June 2026, about sixteen months, and says the compromised credentials have been terminated and enhanced monitoring applied to impacted accounts.
What compensation or protection is TELUS offering?
Two years of complimentary Telus Guardian identity theft protection through Norton, including dark-web and credit monitoring, restoration support and insurance coverage up to $25,000 for stolen funds, $25,000 for personal expenses and $1 million for legal and expert costs. Enrolment closes November 30, 2026.
Who is investigating?
The Vancouver Police Department is investigating, and TELUS has notified the Privacy Commissioner of Canada as part of its obligations under federal privacy law (PIPEDA).
Could the attackers have changed my service or moved my phone number?
The notification states that unauthorized changes were made to some customers’ TELUS services, which is why reviewing your account and adding a port-out PIN or account lock is one of the first recommended steps above.
The bottom line
No ransomware note, no petabyte leak sale, no dramatic disclosure. Just correct passwords used slowly for sixteen months against real customer accounts, and stolen billing data converted into phone calls that sound exactly like your carrier. Enrol in the free protection, lock your account and your number, and treat anyone who quotes your own data back at you as a suspect until proven otherwise. We will update this analysis when TELUS discloses the affected-account count, the credential source, or any findings from the Vancouver Police investigation.









