Telus warns customers after extended account breach
Telus alerted customers that accounts were breached from Feb 2025 to Jun 2026 and that attackers used compromised credentials to access personal and billing information.
Telus notified customers that some consumer accounts were breached between February 2025 and June 2026. Attackers used compromised credentials to view stored account information, including names, account numbers, phone numbers, billing addresses, email addresses, partial payment card numbers, subscription details and payment history.
The obtained data was used in social‑engineering attempts to convince customers to move services to other providers. In some instances, attackers made unauthorized changes to customers’ services. Telus has reset compromised credentials and implemented enhanced security monitoring on impacted accounts.
The company offered affected customers complimentary identity theft protection and reported the activity to the Vancouver Police Department. Telus has not disclosed the number of affected accounts or identified how the login credentials were obtained.
Telus’ description of the incidents is consistent with credential‑stuffing or other account‑takeover campaigns that use previously compromised logins, though the company has not confirmed a third‑party source for the passwords. In March, a Telus subsidiary acknowledged a separate data incident after a criminal group claimed to have taken roughly 1 petabyte of data from the firm’s systems.
Telus is investigating the breaches and coordinating with law enforcement. Customers who suspect their accounts were targeted are being asked to follow Telus’ notifications and to review account statements and service records for unexpected activity.








