2026 Telus Digital — up to ~1 PB claimed (ShinyHunters; strategic exfiltration, non-ransomware)
Data compromised
Customer and internal enterprise data (details emerging); call/support records; code and operational datasets per threat actor and press claims
Technical writeup
Telus Digital confirmed a major cybersecurity incident in March 2026 after ShinyHunters claimed to have stolen nearly 1 petabyte (700–1000 TB) of customer and internal data from cloud environments—framed in press as a targeted intrusion focused on long-horizon data theft rather than ransomware deployment (non-ransomware, “trusted behavior” / insider-like abuse of cloud access in some analyses). Attackers reportedly reused Google Cloud Platform credentials exposed via the broader Salesloft Drift supply-chain incident, then accessed BigQuery and related datasets. Alleged content included PII, call-center and operational records, financial material, law-enforcement backgrounding data in some claims, and source code tied to numerous BPO clients. ShinyHunters demanded ~$65M; Telus publicly declined to pay. Full victim scope and data classes were still emerging in reporting.
Root cause
Credential reuse (Salesloft Drift); GCP/BigQuery access; strategic exfiltration (no ransomware encryption cited for core Telus services)