Telus Notifies Customers After Months-Long Account Takeover Campaign
Telus, one of Canada's largest telecommunications providers, has begun notifying customers that attackers used stolen login credentials to break into a number of consumer accounts and access the personal and billing information stored there. The company confirmed the incident in breach notification letters sent to affected customers, with reports of the notifications surfacing publicly around September 11, 2026.
This is a separate, more recent incident from the March 2026 Telus Digital breach linked to the ShinyHunters group's roughly 1-petabyte data theft (covered previously on CosmicBytez Labs). That earlier incident involved a supply-chain compromise of Telus Digital's cloud infrastructure. This one is an account-takeover campaign against Telus consumer telecom accounts using credentials the attackers already possessed — a different attack surface entirely, even though both involve the same parent company.
Incident Summary
| Field | Details |
|---|---|
| Company | Telus (consumer telecom accounts) |
| Attack Method | Use of stolen/compromised login credentials to access accounts |
| Timeline | February 2025 – June 2026 (approximately 16 months) |
| Customers Affected | Not disclosed — Telus describes it as "a small number of telecom consumer accounts" |
| Public Disclosure | Around September 11, 2026 |
| Law Enforcement | Vancouver Police Department notified; Canada's Privacy Commissioner also contacted |
What Happened
According to Telus's breach notification and public statement, unauthorized parties gained access to a subset of consumer telecom accounts by using credentials that had already been compromised — a pattern consistent with credential stuffing or a similar account-takeover technique, where usernames and passwords leaked from other, unrelated breaches are tested against a target service. Telus has not explicitly confirmed the origin of the credentials the attackers used.
A Telus spokesperson stated:
"We recently identified and blocked unauthorized access to limited information contained in a small number of telecom consumer accounts."
The intrusions reportedly took place over an extended window — February 2025 through June 2026 — suggesting the campaign went undetected or was sustained for well over a year before being identified and shut down.
Data Exposed
Telus said the information accessible through the compromised accounts included:
- Full name and account number
- Phone number(s)
- Billing address
- Preferred language
- Email address
- Partial (last four digits) payment card numbers
- Subscription/service details and charges
- Payment history
Telus has not disclosed the number of customers affected, describing the impact only as touching "a small number" of consumer accounts. That characterization has not been independently verified with a concrete figure, so readers should treat the actual scale as an open question rather than a confirmed small number.
How the Access Was Used
Beyond simply viewing account data, Telus indicated the attackers used their access for more than passive data collection: in some cases, the stolen account access was used to attempt to convince customers to move their services to competitors, and attackers made unauthorized changes to some victims' services. This suggests at least part of the motivation was competitive/fraudulent account manipulation rather than pure data resale, though data exposure (names, billing info, partial card numbers) remains the core privacy risk for affected customers.
Telus's Response
Telus outlined the following remediation steps:
- Reset credentials on affected accounts
- Enhanced security monitoring put in place for impacted accounts
- Notified law enforcement — the Vancouver Police Department — and Canada's Privacy Commissioner
- Offered affected customers two years of complimentary identity theft protection through Norton's "Telus Guardian" service, including dark web monitoring, one-bureau credit monitoring, up to $25,000 reimbursement for stolen funds, up to $1 million in legal/expert coverage, and a free 90-day Norton Security Deluxe subscription
- Enrollment in the protection offer is open until November 30, 2026
What Customers Should Do
- Enroll in the offered identity protection service before the November 30, 2026 deadline if you received a notification
- Change your Telus account password, and avoid reusing it on any other site
- Enable any available multi-factor authentication on your Telus account
- Watch for unsolicited contact encouraging you to switch providers or "confirm" account changes — this campaign specifically involved attackers using account access to push customers toward competitors
- Monitor billing statements and account activity for unauthorized service changes
- Be skeptical of phishing attempts referencing this breach; scammers often piggyback on real breach news to run follow-on social-engineering attacks
Why This Matters
Credential-stuffing and account-takeover campaigns remain effective precisely because so many people reuse passwords across services — a breach at one unrelated site can hand attackers working credentials for accounts at a completely different company, like a telecom provider. A 16-month window between initial access and detection also underscores how account-takeover activity, absent unusual login-pattern detection or customer reports, can persist far longer than a single smash-and-grab breach.
For a company that has now disclosed two distinct security incidents within the same year — the March 2026 Telus Digital/ShinyHunters breach and this September 2026 consumer account-takeover campaign — it also raises broader questions about credential hygiene and account-security controls across the Telus family of services, even though the two incidents do not appear to share a direct technical cause.