Breaches · 5h ago

Telus Account Breach Enabled Service Hijacks

Telus says attackers used compromised credentials to enter consumer accounts between February 2025 and June 2026, exposing customer and billing data for some subscribers. The company says the accessed records included names, account numbers, phone numbers, billing addresses, email addresses, partial payment card numbers, subscription details, and payment history.

The danger was not just reading the file. With those details in hand, attackers could sound legitimate enough to push support-driven changes: Telus says they tried to move customers to competitors and, in some cases, made unauthorized service changes. That means the account itself became an impersonation kit, not just a data bucket.

For telecoms that let account data drive transfers or plan changes, the exposure persists after passwords are reset if the stolen details still help authenticate a caller or impersonator. The reporting does not say how many accounts were hit, but it does show how consumer telecom records can become a control layer over service state and downstream fraud.

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-09-14

Editions

Related stories