What Happened
Telus began notifying customers their accounts were accessed without authorization over a campaign running from February 2025 through June 2026. An attacker used stolen login credentials to reach subscriber records repeatedly across many months rather than in a single break-in, pulling names, account numbers, phone numbers, billing addresses, email addresses, partial payment card numbers, and subscription and payment history from the affected accounts. In some cases, the attacker used the exposed account information to try to convince customers to switch service providers, and made unauthorized changes to victims’ services directly. Telus reset the compromised credentials, added enhanced monitoring to impacted accounts, notified the Vancouver Police Department, and offered complimentary identity theft protection to affected customers. The company has not disclosed how many accounts were affected. Read the original report from SecurityWeek.
Why This Matters for Canadian Organizations
Telus is one of Canada’s three largest wireless carriers, and telecom accounts carry an unusual concentration of information an attacker needs for downstream fraud: billing addresses, partial card numbers, and enough account history to pass a call-center identity check at another company entirely. A campaign running well over a year on reused or stolen credentials points to gaps in login monitoring rather than a single software flaw, the kind of slow-burn compromise many organizations miss because no individual login looks unusual on its own. Under PIPEDA, Telus carries reporting and notification obligations for this breach, and any Canadian business holding comparable account data, telecom, financial services, insurance, faces the same exposure if credential stuffing or reused passwords give an attacker a long runway before detection.
What to Do
Canadian organizations handling customer account data should audit login monitoring for patterns spanning months, not only anomalous single sessions, since long-running low-and-slow access is exactly what evaded detection here. Enforce multi-factor authentication on customer-facing accounts wherever billing or personal data is exposed, and build a customer communication plan in advance, since attackers used exposed data to impersonate Telus and target its own customers after the fact.






