Major Canadian telecom provider Telus has notified customers of a multi-month data breach occurring between 2025 and 2026, exposing sensitive personal and billing information.
- Telus customers' names, phone numbers, and billing details were compromised.
- Attackers used stolen data to attempt service poaching and unauthorized account changes.
- The breach occurred over a multi-month period between February 2025 and June 2026.
- Telus has reset credentials and offered identity theft protection to victims.
Telus, one of Canada’s largest telecommunications providers, has issued an urgent warning to its subscriber base following a significant security breach. The company confirmed that unauthorized actors successfully accessed multiple customer accounts, exposing a wide array of sensitive personal and financial data.
According to official breach notifications, the intrusions took place over an extended period between February 2025 and June 2026. The attackers utilized compromised credentials to penetrate Telus systems, gaining access to highly sensitive information including names, account numbers, phone numbers, billing addresses, email addresses, partial payment card numbers, and detailed subscription and payment histories.
Sophisticated Social Engineering Tactics
The breach goes beyond simple data theft. Telus reported that the stolen information was actively used in sophisticated social engineering attempts. Attackers tried to manipulate customers into switching their services to competitors. In several instances, the perpetrators managed to make unauthorized changes to the victims' existing service plans, causing direct disruption to user connectivity.
While the exact scope of the affected accounts remains undisclosed, the pattern suggests a large-scale credential stuffing or account takeover campaign. In such attacks, hackers use lists of usernames and passwords leaked from other third-party breaches to gain access to unrelated services.
Why This Matters
BozokMedia analysis shows that these types of breaches represent a shift from passive data collection to active exploitation. When attackers combine stolen billing data with social engineering, they create a highly convincing fraud ecosystem that can bypass traditional security awareness training.
The transition from simple data theft to active service manipulation marks a dangerous evolution in cybercriminal tactics.
In response to the crisis, Telus has implemented enhanced security monitoring and forced password resets for all impacted accounts. The company has also engaged the Vancouver Police Department to investigate the matter. To mitigate further damage, Telus is offering complimentary identity theft protection services to those affected by the breach.
This incident follows a period of heightened vulnerability for the company. In March, its subsidiary, Telus Digital, confirmed a massive data breach after the notorious ShinyHunters cybercrime group claimed to have exfiltrated approximately 1 petabyte of data from their systems.
Frequently Asked Questions
1. How can I tell if I am affected?
Telus is directly notifying customers via email or mail if their specific account was compromised during the breach window.
2. What should I do to secure my account?
Change your Telus password immediately and ensure you are using multi-factor authentication (MFA) where available.