TELUS told customers on or around 11 September 2026 that an unauthorised party had accessed a small number of consumer telecom accounts between February 2025 and June 2026, using account credentials. The carrier said it had recently identified and blocked the access. Fields in the accounts included full name, account number, billing address, phone numbers, email, the last four digits of a payment card, service types, charges and payment history. The company did not say how many accounts, despite repeated requests from reporters.
The attackers used the data. TELUS said they contacted customers to lure them to competitors and, in some cases, made unauthorised changes to services. Two years of identity protection were offered. The Office of the Privacy Commissioner of Canada and Vancouver police were notified.
A Foothold Nobody Looked For
Sixteen to eighteen months of access with valid credentials is long for a consumer account and longer for a carrier that sees the logins. TELUS did not say where the credentials came from. SecurityWeek’s reading was credential stuffing or account takeover, which fits a carrier with a large customer base and no second factor on the affected accounts. The corpus files the same mechanism at 26-0526, where one call reached 4.9 million Charter accounts, and the difference here is that nobody noticed for most of two years.
The Notice That Was Called Fake
Customers who received the notification and phoned TELUS to check were told by staff that it was spam. MobileSyrup reported the pattern on 18 September, and the carrier’s public affairs director confirmed a problem, attributed to a technical issue, since corrected. A breach notice that the company’s own front line does not recognise is worse than no notice: the customer who verifies it, which is the right behaviour, is told to ignore it.
What The File Cannot Say
No count, no source of credentials, no discovery date. The file is graded medium for those gaps rather than for any doubt about the incident, which the carrier confirmed. The data was used for poaching customers, which is an unusual motive and suggests a competitor’s reseller or a broker rather than an extortion crew, and that too is an inference the record does not settle.
Compiled from TELUS’s customer notice and statements as reported, listed below. The access window and field list are the carrier’s. No count was published. The credential-stuffing reading is a reporter’s inference and is labelled as one. Graded medium. Corrections: corrections@forensicpost.com.