Security1 publisher2 min readPublished
Telus says stolen credentials gave an attacker 16 months inside consumer telecom accounts
The notifications describe logins with valid passwords, data down to partial payment card numbers, and service changes made without the customer's consent. Telus did not say how many accounts were affected.
The Watch · Security desk

What happened
- Telus is notifying consumer telecom customers that an attacker used compromised credentials to reach their accounts, with the intrusions dated between February 2025 and June 2026.
- The accessed data included names, account numbers, phone numbers, billing addresses, email addresses, partial payment card numbers, subscription details and payment history.
- Telus said it reset the compromised credentials and added enhanced security monitoring to impacted accounts, notified the Vancouver Police Department and offered victims identity theft protection.
- The company has not said how many accounts were affected, and SecurityWeek said it asked for that figure along with the origin of the credentials.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint The reset ends the logins and leaves the copied billing data intact, so the same customer records remain usable for pretext calls long after the accounts are locked down.
- decision For carriers, this puts the alerting burden on the account layer: provisioning changes, service edits and switch requests are the events that would have surfaced this, not perimeter telemetry.
- exposure Affected customers experienced the intrusion as a service change or a pitch to switch providers, and only learn what it was from a notice arriving after the window closed.
February 2025 to June 2026 is about 16 months [1]. Across that window, according to the notifications Telus sent affected customers, the entry path was a valid password [1][2]. Credential-based account takeover looks like a customer logging in. That is why it runs long.
The abuse was noisier than the access. Telus said the account data was used to try to convince customers to move their services to competitors, and that in some cases the attacker made unauthorized changes to the victim's services [4]. Service changes land in a carrier's own provisioning and billing records. Whatever monitoring Telus had over those records did not pull the affected accounts up for review inside the 16 months.
Partial payment card numbers and payment history are the material a convincing pretext call is built from [3]. Those copies survive a password reset.
Where the passwords came from decides whether the reset was enough. SecurityWeek wrote that the brief description suggests a credential stuffing or other account-takeover campaign involving credentials obtained from a third party, and noted that Telus has not said specifically that the abused passwords came from a third party [9][10]. If the credentials came from unrelated dumps and password reuse, resetting them closes this round of logins and the next dump opens another. If they came from Telus, the reset is the fix. SecurityWeek said it asked the company to clarify the source [8].
There is one prior incident on the record. In March, according to SecurityWeek, subsidiary Telus Digital confirmed a data breach after the ShinyHunters cybercrime group claimed to have stolen roughly 1 petabyte of information from its systems [11]. ShinyHunters made the petabyte claim; Telus Digital confirmed the breach [11].
What to watch
- Whether Telus discloses the number of affected consumer accounts.
- Whether Telus identifies the credential source as third-party dumps or its own systems.
- Whether the Vancouver Police Department investigation names who benefited from the attempted switches to competitors.