Telus Customers Hit by Account Breach Spanning More Than a Year
Canada's second-largest phone company says criminals used stolen login details to break into customer accounts, access personal data, and in some cases quietly change people's phone plans.

Key points
- Criminals broke into Telus consumer accounts between February 2025 and June 2026 using stolen login credentials.
- Exposed data includes names, phone numbers, billing addresses, partial payment card numbers, and payment history.
- Some victims had their phone services changed without permission; others were targeted with fake offers to switch carriers.
- Telus has reset the affected passwords and is offering free identity theft protection to victims.
- The number of affected accounts has not been disclosed.
Telus, Canada's second-largest telecommunications company, is sending breach notices to customers whose accounts were broken into over a period spanning more than a year. The intrusions ran from February 2025 to June 2026.
How did the criminals get in?
Telus says attackers used compromised credentials to log in to customer accounts as if they were the real owners. The company has not confirmed where those passwords came from, but the pattern closely matches credential stuffing: an automated attack where criminals take login details leaked from other websites and try them against a different service, counting on people reusing the same password across accounts.
Once inside, the attackers could see names, account numbers, phone numbers, home addresses, email addresses, partial payment card numbers, subscription details, and payment history.
What did the criminals actually do with it?
Two things, according to Telus. Some criminals used the stolen account details to impersonate Telus customers and convince them to switch their phone service to a competitor, a fraud known in the industry as slamming. Others made unauthorized changes to services without the customer's knowledge.
Unauthorized service changes are worth taking seriously. Criminals who can redirect your number to a device they control can intercept the one-time passcodes that banks send by text to verify your identity.
Telus has not said how many accounts were affected.
What has Telus done, and what should customers do?
Passwords on affected accounts have been reset and enhanced security monitoring added. The Vancouver Police Department has been notified, and victims are being offered complimentary identity theft protection.
No notice in your inbox is a reasonable sign your account wasn't in the affected group. Received one? Change your Telus password immediately and check your current plan for anything you didn't authorize. The stolen data includes partial card numbers and billing addresses, so watch your bank statements for unfamiliar charges and consider placing a fraud alert with Equifax or TransUnion.
Should you be more worried about ShinyHunters?
This breach follows a separate incident in March 2025, when Telus subsidiary Telus Digital confirmed a data theft after the ShinyHunters cybercrime group claimed to have stolen roughly one petabyte of data. Whether the two incidents are connected is not known. We've covered ShinyHunters' recent activity closely: the crew's breach of AdaptHealth, affecting 4.1 million patients, ran on 9 September. SecurityWeek first reported Telus's customer notifications.
The blunt read: a window of well over a year before notification is hard to justify, and Telus still hasn't said how many accounts were hit. That silence is itself a reason to keep watching.



