TELUS notified an unspecified number of consumer customers that unauthorized actors accessed their telecom accounts using compromised credentials from February 2025 through June 2026. Exposed information included contact details, account and subscription data, billing and payment history, and partial payment-card information; some victims also experienced unauthorized service changes. TELUS said the attackers may have used the data to persuade customers to transfer service to competing providers.
TELUS reset the compromised credentials, deployed enhanced monitoring, notified affected customers, and offered identity-theft protection services. The company reported the incident to the Vancouver Police Department and the Privacy Commissioner of Canada; it has not disclosed the credential source or number of affected accounts. The exposure creates heightened risk of follow-on social engineering, vishing, SIM-swap, and port-out fraud, and is separate from the March 2026 ShinyHunters intrusion involving TELUS Digital.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
TELUS notified affected consumer customers that compromised credentials had been used to access their accounts and that some victims experienced unauthorized service changes. TELUS terminated affected credentials, added enhanced monitoring, offered identity-theft protection, and reported the incident to the Vancouver Police Department and the Privacy Commissioner of Canada.
TELUS Digital confirmed a separate breach after ShinyHunters claimed to have stolen approximately 1 petabyte of data from its systems. The incident reportedly involved Google Cloud Platform credentials exposed through the Salesloft Drift compromise and an alleged $65 million extortion demand that TELUS did not pay.
Unauthorized individuals used compromised credentials to access a small, undisclosed number of TELUS consumer telecom accounts. The access activity continued through June 2026 and exposed personal, account, billing, service, payment-history, and partial payment-card information.
TELUS-owned Koodo Mobile issued a breach notification involving compromised credentials and unauthorized access to customer data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.