Canadian Telecom Telus Reports Breach by ShinyHunters Group

Telecommunications infrastructure remains a high-value target for both criminal and state-linked actors.

Illustration: Canadian Telecom Telus Reports Breach by ShinyHunters Group
AI-generated illustration · Sylvaris

700 Terabytes Claimed Stolen

In March 2026, Canadian telecommunications firm Telus reported a cybersecurity incident involving unauthorized access to its systems. The ShinyHunters hacking group took responsibility, claiming to have stolen at least 700 terabytes of data.

The exposed files reportedly include personally identifiable information, call data, background check details, and source code. The breach underscores ongoing exposure in the telecommunications sector, which has faced repeated attacks from both criminal groups and state-linked threat actors.

Telecommunications as Critical Infrastructure

Telecommunications networks support both civilian and military operations, making them high-value systemic risks. State-linked actors continue targeting telecommunications networks globally, compromising network edge and core systems to establish persistent access.

The Telus incident follows a pattern of breaches in the sector. Earlier in 2026, Singapore disclosed that China-linked group UNC3886 breached all four of the country's major telecommunications providers in a months-long espionage campaign.

Identity Controls at Network Edge

Security researchers emphasize that identity-based controls at landing stations, network nodes, and across network edges are essential to prevent unauthorized access and limit lateral movement within telecommunications environments.

For organizations, the breach is a reminder that third-party telecommunications providers carry risk that extends beyond service availability. Data flowing through telecom networks may be exposed during transit or at rest in provider systems.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.