Support for Ukraine



Blog Comments




TELUS customer accounts breached over 16 months, followed by confusion over security alerts

Full Story Blog Post Friday, September 25, 2026 in Security   View No Comments No Comments
New Blog PostSecurity
TELUS customer accounts were compromised between February 2025 and June 2026. Personal information and billing details were accessed without authorization. In addition, some customers received legitimate security alerts that were mistakenly identified as scams. Here is what happened and how to protect your account.

NAME

TELUS Customer Accounts Compromised Over 16 Months


In September 2026, TELUS confirmed that unauthorized individuals had accessed certain customer accounts. They used compromised login credentials to gain access.

The unauthorized access occurred between February 2025 and June 2026, spanning a period of 16 months.

Several types of personal information may have been exposed. These include customer names, phone numbers, mailing addresses, and email addresses.

The affected information also includes account numbers and the last four digits of stored payment cards. Subscription details and billing history may have been accessed as well.

Criminals could use this information to make fraudulent communications appear more convincing. For example, they might contact customers and encourage them to switch service providers.

In addition, the information could potentially be used to make unauthorized changes to customer services.

TELUS has not disclosed the exact number of affected customers. However, the company describes the incident as involving a limited number of accounts.

Legitimate Security Alerts Mistaken for Scams


A few days after the incident became public, another problem emerged.

Some customers received emails from TELUS warning them about the potential exposure of their personal information. They contacted customer service to verify whether the messages were legitimate.

According to customer accounts reported by the media, some representatives incorrectly identified the emails as fraudulent. They also advised customers to delete the messages.

However, the emails were genuine security notifications from TELUS.

The messages included a personal code. Affected customers could use this code to claim two years of identity theft protection.

TELUS attributed the confusion to a technical issue. The company says the problem has since been resolved.

Nevertheless, the situation raises an important question for consumers. How can customers identify legitimate security alerts when information from their service provider is contradictory?

Full Story: msn.com



No Comments





Name:
Characters Left   Remember me  
Remembers your name so you do not have to retype it again and stores it encrypted in a cookie file on your computer. Unselect to delete the cookie file or delete your browser cache.

Type CAPTCHA text: