2026 Telus Digital — confirmed intrusion; ShinyHunters extortion; Salesloft/Drift credential tail
Data compromised
BPO customer-support datasets, call metadata/recordings, and enterprise operational files per hacker claims and press-reviewed samples—official censuses still pending at disclosure time
Technical writeup
Telus Digital, the BPO/digital services arm of Telus Corporation, acknowledged unauthorized access to a limited set of systems after ShinyHunters claimed a ~1 PB theft spanning call-center exports, GCP/BigQuery workloads, and downstream Fortune‑500 support tenants. Investigative reporting tied initial access to cloud secrets recycled from the Salesloft Drift mega-compromise, followed by TruffleHog-style secret scanning and multi-month lateral movement. Telus emphasized core consumer connectivity stayed up while forensics and law enforcement scoped customer-specific blast radius.
Root cause
Stolen third-party SaaS/cloud credentials from an upstream supply-chain breach enabling lateral movement into Telus Digital cloud estates