[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f-ZfwgwSrFSpoTM_nYIAOZ6xXwP57rVb_rshysTsqQBI":3},{"article":4,"iocs":42},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"69ce7730-8f93-4304-aefd-54e014368b8c","Telus Warns Customers of Account Breaches","telus-warns-customers-of-account-breaches-1f707a","Stolen credentials were used in a multi-month campaign to access subscriber personal data and billing records. The post Telus Warns Customers of Account Breaches appeared first on SecurityWeek.","Canadian telecom provider Telus is notifying customers about account breaches that occurred between February and June 2025. Attackers used compromised credentials to access subscriber data, including names, contact information, billing details, and partial payment card numbers. The stolen information was used to attempt service transfers to competitors and make unauthorized changes to accounts.","Telus warns customers of account breaches due to stolen credentials accessing personal data.","Telus, one of Canada’s largest telecom providers, is notifying some customers that their accounts have been breached and their personal information has been accessed. In data breach notifications sent to customers whose consumer telecom accounts were affected, Telus said the intrusions occurred between February 2025 and June 2026. According to the company, the attacker used compromised credentials to access Telus accounts and the information they store, including names, account numbers, phone numbers, billing addresses, email addresses, partial payment card numbers, subscription details, and payment history. Telus said the obtained account information has been used to attempt to convince customers to move their services to competitors, and in some cases the attackers made unauthorized changes to the victim’s services. It’s unclear how many accounts the breach affected. Telus said it has reset the compromised credentials and added enhanced security monitoring to impacted accounts. The Vancouver Police Department has been notified, and victims have been offered complimentary identity theft protection services. Advertisement. Scroll to continue reading. Telus’ brief description of the incident suggests the accounts were targeted in a credential stuffing or other account-takeover campaign involving credentials obtained from a third party. However, the company has not said specifically that the abused passwords came from a third party. In March, subsidiary Telus Digital confirmed suffering a data breach after the notorious ShinyHunters cybercrime group claimed to have stolen roughly 1 petabyte of information from the company’s systems. SecurityWeek has reached out to Telus for additional information, including the number of affected accounts and clarification on the source of the credentials the attacker abused. Related: Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack Related: Surfshark Systems Targeted by Hackers Related: 4.1 Million Impacted by AdaptHealth Data Breach Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Trezor Says 347,000 Users Received Phishing Emails After Brevo HackUkrainian Conti Ransomware Developer Sentenced to 4 Years in US PrisonAnthropic Says Russian Hackers Used Claude AI to Automate Malware EvasionCybersecurity M&A Roundup: 33 Deals Announced in August 2026Widened Scan Turns Up Fourth Rogue Claude Cyber IncidentOrganizations Warned of Cisco Secure FMC ExploitationRockwell Automation Patches Over a Dozen Vulnerabilities Across ProductsAnthropic Details Response to Security Incidents, Unveils Enterprise Safeguards Latest News Three JFrog Artifactory Flaws Exploited for Backdoor DeploymentConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like AttacksAnthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch UpBlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-DaysUsers in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic SaysPhishing Research Challenges Conventional Security Awareness TestingGitLab Vulnerability Exploited One Day After DisclosureIn Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveZero Networks has named Yossi Dagan as Chief Financial Officer.Manifold has appointed Joe Sullivan to its Board of Directors.Patrick McKinney has joined Turing as Chief Information Security Officer.More People On The MoveExpert Insights This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Ftelus-warns-customers-of-account-breaches\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2026\u002F09\u002FTelus.jpeg","2026-09-14T09:56:57+00:00","2026-09-14T10:00:07.897443+00:00",7,[18,21],{"name":19,"type":20},"Telus","vendor",{"name":22,"type":23},"ShinyHunters","threat_actor","2e06f76c-d5b9-4f54-9eef-4d3447b10730",{"id":24,"icon":26,"name":27,"slug":28},null,"Breaches","breaches",[30,35,37],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":36},{"id":24,"icon":26,"name":27,"slug":28},{"category":38},{"id":39,"icon":26,"name":40,"slug":41},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]