Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2815+ Articles
167+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Telus Warns Customers of Account Breaches
Telus Warns Customers of Account Breaches
NEWS

Telus Warns Customers of Account Breaches

Telus says stolen credentials were used over 16 months to access customer accounts and billing data; scope of impact undisclosed.

Dylan H.

News Desk

September 14, 2026
5 min read

Telus Notifies Customers After Months-Long Account Takeover Campaign

Telus, one of Canada's largest telecommunications providers, has begun notifying customers that attackers used stolen login credentials to break into a number of consumer accounts and access the personal and billing information stored there. The company confirmed the incident in breach notification letters sent to affected customers, with reports of the notifications surfacing publicly around September 11, 2026.

This is a separate, more recent incident from the March 2026 Telus Digital breach linked to the ShinyHunters group's roughly 1-petabyte data theft (covered previously on CosmicBytez Labs). That earlier incident involved a supply-chain compromise of Telus Digital's cloud infrastructure. This one is an account-takeover campaign against Telus consumer telecom accounts using credentials the attackers already possessed — a different attack surface entirely, even though both involve the same parent company.


Incident Summary

FieldDetails
CompanyTelus (consumer telecom accounts)
Attack MethodUse of stolen/compromised login credentials to access accounts
TimelineFebruary 2025 – June 2026 (approximately 16 months)
Customers AffectedNot disclosed — Telus describes it as "a small number of telecom consumer accounts"
Public DisclosureAround September 11, 2026
Law EnforcementVancouver Police Department notified; Canada's Privacy Commissioner also contacted

What Happened

According to Telus's breach notification and public statement, unauthorized parties gained access to a subset of consumer telecom accounts by using credentials that had already been compromised — a pattern consistent with credential stuffing or a similar account-takeover technique, where usernames and passwords leaked from other, unrelated breaches are tested against a target service. Telus has not explicitly confirmed the origin of the credentials the attackers used.

A Telus spokesperson stated:

"We recently identified and blocked unauthorized access to limited information contained in a small number of telecom consumer accounts."

The intrusions reportedly took place over an extended window — February 2025 through June 2026 — suggesting the campaign went undetected or was sustained for well over a year before being identified and shut down.


Data Exposed

Telus said the information accessible through the compromised accounts included:

  • Full name and account number
  • Phone number(s)
  • Billing address
  • Preferred language
  • Email address
  • Partial (last four digits) payment card numbers
  • Subscription/service details and charges
  • Payment history

Telus has not disclosed the number of customers affected, describing the impact only as touching "a small number" of consumer accounts. That characterization has not been independently verified with a concrete figure, so readers should treat the actual scale as an open question rather than a confirmed small number.


How the Access Was Used

Beyond simply viewing account data, Telus indicated the attackers used their access for more than passive data collection: in some cases, the stolen account access was used to attempt to convince customers to move their services to competitors, and attackers made unauthorized changes to some victims' services. This suggests at least part of the motivation was competitive/fraudulent account manipulation rather than pure data resale, though data exposure (names, billing info, partial card numbers) remains the core privacy risk for affected customers.


Telus's Response

Telus outlined the following remediation steps:

  • Reset credentials on affected accounts
  • Enhanced security monitoring put in place for impacted accounts
  • Notified law enforcement — the Vancouver Police Department — and Canada's Privacy Commissioner
  • Offered affected customers two years of complimentary identity theft protection through Norton's "Telus Guardian" service, including dark web monitoring, one-bureau credit monitoring, up to $25,000 reimbursement for stolen funds, up to $1 million in legal/expert coverage, and a free 90-day Norton Security Deluxe subscription
  • Enrollment in the protection offer is open until November 30, 2026

What Customers Should Do

  • Enroll in the offered identity protection service before the November 30, 2026 deadline if you received a notification
  • Change your Telus account password, and avoid reusing it on any other site
  • Enable any available multi-factor authentication on your Telus account
  • Watch for unsolicited contact encouraging you to switch providers or "confirm" account changes — this campaign specifically involved attackers using account access to push customers toward competitors
  • Monitor billing statements and account activity for unauthorized service changes
  • Be skeptical of phishing attempts referencing this breach; scammers often piggyback on real breach news to run follow-on social-engineering attacks

Why This Matters

Credential-stuffing and account-takeover campaigns remain effective precisely because so many people reuse passwords across services — a breach at one unrelated site can hand attackers working credentials for accounts at a completely different company, like a telecom provider. A 16-month window between initial access and detection also underscores how account-takeover activity, absent unusual login-pattern detection or customer reports, can persist far longer than a single smash-and-grab breach.

For a company that has now disclosed two distinct security incidents within the same year — the March 2026 Telus Digital/ShinyHunters breach and this September 2026 consumer account-takeover campaign — it also raises broader questions about credential hygiene and account-security controls across the Telus family of services, even though the two incidents do not appear to share a direct technical cause.


Sources

  • SecurityWeek — Telus Warns Customers of Account Breaches

Related Reading

  • Telus Digital Confirms Massive Breach After ShinyHunters
#Telus#Data Breach#Credential Stuffing#Account Takeover#Canada#Telecom

Related Articles

Telus Digital Confirms Massive Breach After ShinyHunters

Canadian telecom giant Telus Digital has confirmed a security incident after the ShinyHunters hacking group claimed to have stolen nearly 1 petabyte of...

5 min read

Chick-fil-A Discloses Data Breach After Credential Stuffing Attacks

Chick-fil-A is notifying customers across 10 states after credential stuffing attacks between June 17–19, 2026 compromised One loyalty accounts, exposing...

5 min read

FBI: Hackers Using Social Engineering to Breach Accounts and Steal Explicit Content

The FBI warns hackers are breaching social media accounts to steal explicit content via credential stuffing, impersonation, and fake clone sites.

3 min read
Back to all News