A man in Surrey gets a call from “Telus retention” the week after his renewal notice. The caller has his account number, his billing address, the last four digits of his card and the exact amount of his last payment, and offers a loyalty credit if he confirms the card. He has no reason to doubt it: everything the voice knows is on his real bill. That is what the Telus breach put in a stranger’s hands, and Telus says the people who took it have already been phoning customers.
Confirmation: confirmed by the company. Telus told affected customers, and Daily Hive on 11 September 2026, that it “recently identified and blocked unauthorized access to limited information contained in a small number of telecom consumer accounts.”
What happened
Between February 2025 and June 2026, people using compromised login credentials signed in to Telus consumer accounts and read what was inside, and Telus began notifying the affected customers in September 2026. That is the timeline in the customer notice reported by Daily Hive on 11 September and by SecurityWeek on 14 September. Sixteen months is a long window, and Telus has not said when it first noticed.
Telus has not said where the credentials came from. SecurityWeek describes the pattern as “a credential stuffing or other account-takeover campaign”: a password leaked from some other site, tried against Telus logins until one worked. Telus has not confirmed that reading, and it has not published a number. Its own words are “a small number of telecom consumer accounts.” SecurityWeek and Daily Hive both note the count is undisclosed.
What the intruders did with the access is the unusual part. According to the notice, they contacted customers to persuade them to switch to a competitor, and in some cases made unauthorised changes to the customer’s Telus services. Telus says it has reset the compromised credentials, added monitoring to the affected accounts, notified law enforcement and the Office of the Privacy Commissioner of Canada, and is offering two years of Telus Guardian identity protection, provided by Norton, with an enrolment deadline of 30 November 2026.
What was exposed
Every affected account gave up the full name, account number, billing address, preferred language and phone number, and most also gave up the email address, the last four digits of the payment card, the services on the account, the charges and the payment history. What each item is worth to the person holding it:
- Name, account number and billing address. Enough to pass as Telus on the phone, and enough to pass as you to Telus, depending on what the agent asks for.
- Phone number and email address. The two delivery routes for the follow-up. A text about “your Telus account”, an email with your account number in the subject line.
- Last four digits of your card. Not enough to charge it. Exactly enough to make “we have your card ending in 4471 on file, can you confirm the rest” sound like a real call.
- Services, charges and payment history. The detail that turns a generic scam into one that quotes your own bill back to you.
- Preferred language. The scam arrives in the language you actually answer in.
No passwords are listed as taken from Telus. The password problem runs the other way: a password was what got them in, which means it was already out there before this started.
What to do now
Most of this is about your logins and your phone, not about OptMsg, and the first two steps take ten minutes.
1. Change your Telus password to one you have used nowhere else. If the same password is on your email account, change that one first. A password manager makes every account its own password and stops this attack at the door. 2. Turn on the strongest sign-in your email account offers. Your email is how most accounts get reset, Telus included. A passkey where available, an authenticator app otherwise. 3. Treat any call, text or email about your Telus account as unverified until you started it. Hang up and call the number on your bill. Telus’s own advice in the notice is to be wary of unsolicited service offers by phone and at the door, and to contact them about any account change you did not make. 4. Check your Telus account for changes you did not make: added lines, plan changes, a new contact email or a forwarded number. A changed contact email is how a takeover survives a password reset. 5. Enrol in the Telus Guardian offer before 30 November 2026 if your notice includes it. Dark web and credit monitoring will show you if the data resurfaces. 6. Search your address at Have I Been Pwned. If the credential came from an older leak, that is the list of other accounts still open to the same trick.
How OptMsg changes this exposure
Honestly, and at its real size: OptMsg would not have prevented this. The login that was reused was a Telus login, and the data came out of Telus’s systems. What an opt-in inbox with no password changes is what a leaked credential is worth against you afterwards.
Your OptMsg account has no password, so a password stolen from another site can’t open your inbox. That is the attack Telus is describing, aimed at the one account that resets every other one. Credential stuffing needs a password to try. Your OptMsg account doesn’t have one. So when the next site leaks the pair, the login they leak isn’t the login to your inbox.
And the follow-up email, the one that opens with your account number and asks you to confirm the card, has a shorter path. Mail from a sender you have not approved goes to Trash, not your Inbox, and auto-deletes after 30 days. OptMsg’s patent-pending opt-in technology means the message from a look-alike domain the real Telus has not used lands in Trash, not in front of you at 8 a.m. with your own bill quoted back. The genuine Telus reaches your Inbox once you approve it. Only people you approve can reach your inbox. Everyone else goes to Trash. And if a message in Trash comes from a sender many other OptMsg users have opted in to, you get a push alert, so a real notice is not lost.
What that does not cover: the phone call, which is the route Telus says these intruders actually used; a phishing page you open yourself; a message from a sender you did approve whose own account was taken; a compromised device; or someone with your unlocked phone. Those are the six steps above, and the third one is the whole defence against the call.
If you want the account that resets everything else to be the one with no password to steal, see how Simple by Design works, or read why your inbox should not care about a leaked password.
Ready for an inbox a stolen password cannot open? Create Your Account.
Your Inbox. Your Rules.
Frequently asked questions
What happened in the Telus data breach? Between February 2025 and June 2026, people using compromised login credentials accessed a number of Telus consumer accounts and read the customer information inside. Telus notified affected customers in September 2026, reset the credentials, and reported it to law enforcement and the Privacy Commissioner of Canada.
How many Telus customers were affected? Telus has not said. Its notice describes “a small number of telecom consumer accounts,” and neither Daily Hive nor SecurityWeek has a figure.
What information was exposed in the Telus breach? For every affected account: full name, account number, billing address, preferred language and phone numbers. For most: email address, last four digits of the payment card, services, charges and payment history.
Was my Telus password stolen? Telus has not listed passwords among the data taken. The intruders got in with credentials that were already compromised, which points to a password reused from another site. Change your Telus password to a unique one either way.
Would OptMsg have stopped the Telus breach? No. It happened at Telus. What OptMsg changes is the aftermath: there is no password on an OptMsg account for a leaked credential to match, and mail from a sender you have not approved goes to Trash rather than your Inbox.
Sources
- Daily Hive: Telus confirms ‘unauthorized access’ to some customers’ personal information — 11 September 2026
- SecurityWeek: Telus Warns Customers of Account Breaches — 14 September 2026