Desk live·
ForensicPost
Breaches/Telecom/File 26-0911

TELUS Says Accounts Were Accessed for 16 Months; Its Staff Then Called the Notice Spam

The Canadian carrier notified a small number of customers on 11 September that someone had used their credentials from February 2025 to June 2026, read their billing records and in some cases changed their services. Customers who called to check were told the letter was fake.

Constructed geometry · not a chart of case data
JurisdictionCanadaVancouverthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetTELUS consumer accounts
ActorUnattributed
D. Kennedy9 min readConfidence: medium4 sources reviewed

TELUS told customers on or around 11 September 2026 that an unauthorised party had accessed a small number of consumer telecom accounts between February 2025 and June 2026, using account credentials. The carrier said it had recently identified and blocked the access. Fields in the accounts included full name, account number, billing address, phone numbers, email, the last four digits of a payment card, service types, charges and payment history. The company did not say how many accounts, despite repeated requests from reporters.

The attackers used the data. TELUS said they contacted customers to lure them to competitors and, in some cases, made unauthorised changes to services. Two years of identity protection were offered. The Office of the Privacy Commissioner of Canada and Vancouver police were notified.

A Foothold Nobody Looked For

Sixteen to eighteen months of access with valid credentials is long for a consumer account and longer for a carrier that sees the logins. TELUS did not say where the credentials came from. SecurityWeek’s reading was credential stuffing or account takeover, which fits a carrier with a large customer base and no second factor on the affected accounts. The corpus files the same mechanism at 26-0526, where one call reached 4.9 million Charter accounts, and the difference here is that nobody noticed for most of two years.

The Notice That Was Called Fake

Customers who received the notification and phoned TELUS to check were told by staff that it was spam. MobileSyrup reported the pattern on 18 September, and the carrier’s public affairs director confirmed a problem, attributed to a technical issue, since corrected. A breach notice that the company’s own front line does not recognise is worse than no notice: the customer who verifies it, which is the right behaviour, is told to ignore it.

What The File Cannot Say

No count, no source of credentials, no discovery date. The file is graded medium for those gaps rather than for any doubt about the incident, which the carrier confirmed. The data was used for poaching customers, which is an unusual motive and suggests a competitor’s reseller or a broker rather than an extortion crew, and that too is an inference the record does not settle.

How we reported this

Compiled from TELUS’s customer notice and statements as reported, listed below. The access window and field list are the carrier’s. No count was published. The credential-stuffing reading is a reporter’s inference and is labelled as one. Graded medium. Corrections: corrections@forensicpost.com.

Sources
  1. Telus confirms some customers’ personal information exposed in data breachMobileSyrup
  2. Telus Warns Customers of Account BreachesSecurityWeek
  3. Telus data breach confusion caused by “technical issue”MobileSyrup
  4. TELUS hit by data security incident after 18 months of unauthorised accessteiss
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary