September 14, 2026
Telus Warns Customers After Multi-Month Account Takeover Campaign Exposed Billing and Subscriber Data
Telus is notifying customers that attackers used compromised credentials to access consumer telecom accounts between February 2025 and June 2026, exposing names, account numbers, phone numbers, billing addresses, email addresses, partial payment card numbers, subscription details, and payment history. The stolen data was used to try to move customers to competitors, and in some cases attackers made unauthorized service changes. Telus has reset credentials and added enhanced monitoring.
A long-running credential-stuffing style campaign against customer account services shows why account-takeover and abuse detection on customer-facing APIs must run continuously, not just at login.