Incident
Published 2026-09-14
Verified 2026-09-19

Telus warns customers of multi-month account breaches via stolen credentials

SecurityWeek (14 September 2026) reports Telus is notifying some Canadian consumer telecom customers that attackers accessed their accounts between February 2025 and June 2026 using compromised credentials. Accessed data included names, account numbers, phone numbers, billing addresses, email addresses, partial payment card numbers, subscription details, and payment history. Telus says the stolen account information was used to push customers toward competitors and, in some cases, to make unauthorised service changes. Impacted credentials were reset and enhanced monitoring applied; Vancouver Police were notified and complimentary identity-theft protection offered. Headcount and exact credential source were not published; the description is consistent with credential stuffing or other account takeover using third-party credentials, which Telus has not explicitly confirmed. Distinct from the March Telus Digital / ShinyHunters incident. Primary/wire: SecurityWeek pending a public Telus notice URL.

Product
Telus consumer telecom accounts (Canada)
Versions
n/a (credential-based account takeover; not a product CVE)
Exploited in Australia?
unknown
Patch to
n/a for other operators: force password resets on suspected ATO, monitor SIM/port and plan-change abuse, offer identity monitoring where appropriate

Primary: SecurityWeek — Telus account breaches (14 Sep 2026)

breaches identity