TELUS is notifying customers of a data breach after unauthorized individuals used compromised credentials to access customer accounts, exposing personal, billing and payment-related information.
According to breach notifications sent to affected customers, the unauthorized access occurred sometime between February 2025 and June 2026. TELUS said the individuals behind the activity may have used information obtained from customer accounts to contact subscribers and attempt to persuade them to move their services to competitors, or to make unauthorized changes to their TELUS services.
The potentially lengthy access window stands out. TELUS has not publicly clarified whether the February 2025 to June 2026 period represents continuous unauthorized access, multiple instances of account access, or the broader period during which the compromised credentials could have been abused.
Billing and payment information accessed
TELUS said its investigation determined that affected accounts exposed customers’ full names, account numbers, billing addresses, preferred languages and phone numbers. Email addresses were also exposed in most cases.
Additional information accessed included the last 4 digits of payment cards stored on accounts, the types of TELUS services customers subscribed to, amounts charged for those services and payment history.
TELUS has not indicated that full payment card numbers, passwords or government identification numbers were exposed in this incident.
The combination of contact information, account identifiers, subscribed services and billing history could nevertheless make affected customers more vulnerable to convincing impersonation and social engineering attempts. An attacker already familiar with a customer’s TELUS account and recent billing information could potentially use those details to make fraudulent communications appear legitimate.
Compromised credentials used to access accounts
The notification attributes the incident to compromised credentials but does not identify whose credentials were stolen or explain how they were initially obtained.
TELUS said it terminated the compromised credentials to prevent further unauthorized access and placed notes on affected accounts documenting the incident. The company has also introduced enhanced security monitoring, which may result in affected customers being asked additional verification questions when contacting TELUS.
The telecommunications provider reported the incident to the Vancouver Police Department and said it is cooperating with the investigation.
Affected customers are also being offered 2 years of complimentary TELUS Guardian identity theft protection through Norton. TELUS has maintained a partnership with Norton since 2023 that includes breach response and identity protection services.
Incident appears separate from earlier ShinyHunters breach
The newly disclosed customer-account incident appears separate from a major cyberattack disclosed by TELUS Digital earlier in 2026 and claimed by ShinyHunters.
TELUS Digital confirmed in March that an unauthorized actor had accessed a limited number of its systems. The company said its operations remained fully functional and that it had engaged cyber forensics experts and law enforcement while investigating the scope of potentially affected data.
ShinyHunters subsequently claimed responsibility for that intrusion and alleged it had stolen approximately 1 petabyte of data. Samples shared with journalists reportedly included personally identifiable information associated with multiple TELUS Digital business customers and call center recordings. The group also claimed it obtained access after discovering TELUS credentials within data stolen during the 2025 Salesloft compromise.
TELUS Digital said at the time that it had no reason to believe the intrusion extended to other TELUS Corporation business units, including its consumer mobility and home services operations.
That distinction is important because the latest notifications specifically concern TELUS customer accounts. They describe compromised credentials being used between February 2025 and June 2026 to access account information and potentially solicit customers or make unauthorized service changes.
No evidence currently establishes that ShinyHunters was responsible for the newly disclosed customer-account breach or that the 2 incidents share the same intrusion method. TELUS has not attributed the latest incident to a known threat actor.
Customers face elevated impersonation risk
The apparent purpose of the unauthorized access is unusual compared with breaches focused primarily on bulk data theft. TELUS specifically warned that the individuals may have used account information to contact customers in attempts to move their services to competing providers.
Customers receiving unsolicited calls, emails or text messages concerning their TELUS accounts should therefore be cautious when a caller references legitimate account or billing details. Possession of accurate personal information does not establish that a communication originated from TELUS.
TELUS advises customers who believe they have been targeted by fraud to contact the company through its official support channels. The company also maintains security guidance for reporting suspected fraud, phishing and cybersecurity issues.
TELUS has not publicly disclosed how many customers were affected by the latest incident. The notification also does not identify the individuals responsible for the unauthorized access or explain how many accounts were accessed during the February 2025 to June 2026 period.












