Download Privacy Needle App

Type to search

Data Breaches

Telus Notifies Customers of Multi-Month Account Breach

Share

Telus, a major Canadian telecommunications provider, has notified customers that their accounts were compromised in a breach spanning several months.

The company stated that the intrusions occurred between February 2025 and June 2026, during which attackers used stolen credentials to gain unauthorised access to subscriber profiles.

Exposed Data and Fraudulent Activity

The information accessed during the campaign included names, account numbers, phone numbers, billing addresses, and email addresses. Attackers also obtained partial payment card numbers, subscription details, and payment histories.

Beyond the theft of information, the breach had operational consequences. Telus reported that attackers used the stolen data to attempt to persuade customers to move their services to competing providers. In some instances, the attackers also made unauthorised changes to the affected accounts.

Company Response and Historical Context

Telus has reset the compromised credentials and implemented enhanced security monitoring for all impacted accounts. The company has notified the Vancouver Police Department and is providing complimentary identity theft protection services to affected victims.

The nature of the incident suggests a credential stuffing or account takeover (ATO) campaign, likely involving credentials obtained from a third party. While the company has not explicitly confirmed the specific source of the passwords, this method involves using previously leaked login details to gain access to unrelated services.

This incident follows a significant security event involving Telus Digital, a subsidiary of the company. In March, the cybercrime group ShinyHunters claimed to have exfiltrated approximately one petabyte of data from the subsidiary’s systems.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.