TELUS A.I CyberSecurity Scoring
TELUS
Company Information
Website:http://www.telus.com
Employees number:38,811
Number of followers:442,319
NAICS:517
Industry Type:Telecommunications
Homepage:telus.com
TELUS Risk Score (AI oriented)
Between 0 and 549
TELUSTelecommunications
Updated:
29/07/2026
29/07/2026
295/1000
Critical
C
TELUS Global Score (TPRM)
xxxx
TELUSTelecommunications
Score locked

TELUSCritical
Current Score
295C (CRITICAL)
01000
8 incidents
-104.67 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
284
JULY 2026
288
JUNE 2026
280
MAY 2026
269
APRIL 2026
329
Breach
17 Apr 2026 • TELUS
Loblaw and Telus Digital: Canada Life breach exposes data of up to 70,000 people – mostly customers
Canada Life Cyber Incident Exposes Personal Data of Up to 70,000 Individuals
262
CRITICAL-67
LOBTEL1776782580
Canada Life Cyber Incident Exposes Personal Data of Up to 70,000 Individuals
Canada Life has confirmed a cybersecurity incident involving unauthorized access to customer data through a compromised employee account. The breach, detected in recent weeks, exposed personal information including names, addresses, dates of birth, phone numbers, and account numbers for up to 70,000 individuals, primarily employees covered under a large corporate group benefits plan. Payment details and passwords were not compromised.
The attack was traced to the criminal group ShinyHunters, which gained access via a subcontractor’s account linked to Freedom Mobile’s platform. Canada Life has engaged third-party cybersecurity experts to investigate and has notified authorities. While the company stated the incident was contained and operations remain unaffected, affected individuals will be contacted directly and offered free credit monitoring.
The breach follows a pattern of recent cyber incidents in Canada, including a Loblaw breach exposing basic customer data (names, emails, and phone numbers) and a Telus Digital intrusion also attributed to ShinyHunters. Earlier in 2025, a phishing attack disclosed in August revealed a far larger compromise than initially reported, affecting 750,000 investors with sensitive financial data.
Canada Life emphasized its commitment to customer protection and is working to assess the full scope of the impact. The incident underscores the growing threat of cyberattacks targeting employee accounts and third-party vulnerabilities in corporate systems.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
437
Breach
13 Mar 2026 • TELUS
Shoppers Drug Mart, President’s Choice, Loblaw, No Frills and PC Optimum: “Threat Actor” on the dark web claims Loblaw’s “low-level” data breach is a much larger threat
Alleged Massive Data Breach at Loblaw
319
CRITICAL-118
NO-SHOPRELOB1773534483
Loblaw Faces Alleged Massive Data Breach as Threat Actor Demands Response
A threat actor operating under the handle "igotafeeling" on the DarkWeb Informer forum has claimed to have breached Loblaw, Canada’s largest food and pharmacy retailer, which owns brands like President’s Choice, No Frills, Shoppers Drug Mart, Real Canadian Superstore, and the PC Optimum loyalty program.
The actor alleges possession of over 1.8 billion records, including:
- 75.1 million Salesforce customer records (names, emails, phone numbers, addresses, loyalty IDs, and health card numbers)
- 724.9 million Shoppers Drug Mart records (passwords, tokens, loyalty IDs, payment details, and full credit card numbers with expiry dates)
- 129.9 million pharmacy fill requests (prescription numbers and patient IDs)
- 120.4 million e-commerce fraud-feed records (payment card BINs, last-four digits, and expiry dates)
- 20.2 million Delivery Ops Portal records (orders, deliveries, and postal codes)
- 3,014 GitLab projects containing Loblaw’s full source code
- 19.3 million Oracle identity records (MFA device details and credentials)
- 55.3 million marketing and email records across 673 tables
The threat actor has given Loblaw until March 19 to respond, accusing the company of "ghosting" them and dismissing customer and investor concerns. They have also invited media organizations to verify the data’s authenticity.
In response, Loblaw issued a March 12 press release, labeling the incident a "low-level data breach" and stating that only "basic customer information" (names, phone numbers, and emails) may have been accessed. The company explicitly denied evidence of financial or credit card data compromise directly contradicting the threat actor’s claims.
While the breach remains unverified, the scale of the alleged exposure if confirmed would rank among the largest in Canadian history. The situation mirrors past high-profile breaches (e.g., T-Mobile, Equifax, Capital One), where initial corporate statements downplayed impact before later revelations proved otherwise.
Loblaw customers with PC Optimum accounts, Shoppers Drug Mart loyalty cards, or prescription histories may be affected if the claims hold true. The deadline for Loblaw’s response is six days away.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
491
Breach
12 Mar 2026 • TELUS
Crunchyroll and Telus: Cyber Security News ®’s Post
Crunchyroll Suffers Major Data Breach: 100 GB of PII Exfiltrated
319
CRITICAL-172
CRUTEL1774239823
Crunchyroll Suffers Major Data Breach: 100 GB of PII Exfiltrated
A threat actor claims to have stolen approximately 100 GB of personally identifiable information (PII) from Crunchyroll, the Sony-owned anime streaming platform, following a breach on March 12, 2026. The attack reportedly originated from a compromised employee account at Telus, Crunchyroll’s outsourcing partner, which provided the attacker with initial access to the company’s internal systems.
Once inside, the threat actor conducted lateral movement, infiltrating sensitive customer-facing infrastructure, including Crunchyroll’s ticketing systems. As of this report, Crunchyroll has not publicly confirmed the breach, leaving the full scope and impact of the incident unclear. The exfiltrated data’s nature and potential exposure of user details remain unconfirmed.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
545
Breach
11 Mar 2026 • TELUS
Wynn Resorts and Telus: Telus Investigating Major Cybersecurity Breach After Hackers Claim Massive Data Theft
Telus Cybersecurity Breach Investigation
437
CRITICAL-108
WYNTEL1773347843
Telus Investigates Cybersecurity Breach as ShinyHunters Claims Massive Data Theft
Canadian telecommunications provider Telus is probing a cybersecurity incident after the hacking group ShinyHunters alleged it stole up to 700 terabytes of data from the company’s systems. The Vancouver-based firm confirmed on Thursday that it detected unauthorized access to certain internal systems but stated that business operations and customer services remain unaffected.
Telus has engaged digital forensics experts and is collaborating with law enforcement to assess the breach’s scope. While the company has not confirmed the volume or nature of compromised data, samples shared by ShinyHunters with Reuters reportedly include personally identifiable information, call records, FBI background check details, and software source code linked to multiple corporate divisions. Reuters has not independently verified the data’s authenticity.
ShinyHunters, a group with a history of high-profile attacks, has previously targeted organizations like Dutch telecom Odido, PornHub, and Wynn Resorts. The group recently claimed responsibility for a breach exposing over six million Odido customer accounts.
Telus continues its investigation to determine how the intrusion occurred and whether sensitive customer or partner data was accessed. The company has begun notifying affected individuals where necessary.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
544
JANUARY 2026
636
Breach
01 Jan 2026 • TELUS
Loblaw, Telus Digital, Fido, Rogers and Ardene: Average Canadian data breach costs and detection times are rising: IBM report
Canadian Data Breaches Hit Record Costs in 2026, IBM Report Finds
527
CRITICAL-109
FIDLOBROGARDTEL1785321269
Canadian Data Breaches Hit Record Costs in 2026, IBM Report Finds
A new report from IBM reveals that data breaches in Canada reached an average cost of $7.11 million per incident in 2026, up from $6.98 million in 2025. The breaches exposed an average of 28,500 records an 8% increase from the previous year and took 205 days to detect and contain, a 6% rise in response time.
The rising costs stem from the complex aftermath of breaches, including business disruption, recovery efforts, legal obligations, and customer communications, according to Chris Sicard, IBM Canada’s security leader. Some companies even pass recovery expenses to clients, amplifying the financial strain.
The report defines data breaches as incidents compromising personally identifiable, financial, medical, or proprietary information, with some attacks exposing up to 115,380 records. High-profile Canadian companies including Rogers, Fido, Telus Digital, Loblaw, Canada Computers, and Ardene have reported breaches in 2026.
Energy companies faced the highest average breach costs at $9.21 million, followed by technology firms ($9.02 million) and industrial organizations ($8.89 million). Sicard attributed the higher costs to their larger networks, sensitive data, and low tolerance for downtime, making them prime targets for attackers.
The report also highlighted the role of AI in cybersecurity, with organizations using AI extensively reporting lower breach costs ($5.5 million vs. $8.91 million) and faster response times 124 days to detect and 57 to contain, compared to 154 days and 71 days for non-AI adopters. AI is increasingly used for vulnerability patching, breach detection, and containment, improving efficiency in mitigating attacks.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
636
NOVEMBER 2025
633
OCTOBER 2025
630
SEPTEMBER 2025
626
AUGUST 2025
674
Breach
01 Aug 2025 • TELUS
Telus Corp.: Canadian Telecom Telus Says It’s Investigating Cyber Breach
Telus Cybersecurity Breach Linked to ShinyHunters Extortion Group
620
CRITICAL-54
TEL1773405027
Telus Investigates Cybersecurity Breach Linked to ShinyHunters Extortion Group
Canadian telecommunications giant Telus Corp. is probing a cybersecurity incident involving unauthorized access to a limited number of its systems. The company confirmed the breach in a statement, noting that immediate steps were taken to contain the intrusion and secure affected systems. Telus is actively monitoring the situation and has begun notifying impacted customers.
The breach was claimed by ShinyHunters, an extortion group that contacted Bloomberg News this week, alleging they stole a large volume of data from Telus in a supply chain attack in August. The group claimed to have sent a ransom note in February, demanding payment in Bitcoin though the exact amount was redacted. According to ShinyHunters, the exposed data includes information belonging to Telus’ customers, which span technology companies and banks.
Telus, one of Canada’s largest mobile and broadband providers, stated it is collaborating with law enforcement and cyber forensics experts while maintaining that business operations remain unaffected. There is no evidence of disruption to connectivity or services. The company did not directly address ShinyHunters’ claims or name the group in its response.
Following the news, Telus shares dipped 0.6%, trading at C$17.93 in Toronto. The incident underscores growing risks in third-party supply chain attacks targeting major telecommunications providers.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2025
766
Breach
01 Mar 2025 • TELUS
Loblaw, Telus Digital, Rogers, Ardene and Fido: Average Canadian data breach costs and detection times are rising: IBM report
Canadian Data Breaches Hit Record Costs as AI Emerges as a Key Defense
658
CRITICAL-108
SIMLOBROGARDTEL1785321665
Canadian Data Breaches Hit Record Costs as AI Emerges as a Key Defense
Canadian companies faced rising financial and operational fallout from data breaches in 2026, with average costs climbing to $7.11 million per incident up from $6.98 million in 2025 according to an IBM report released this week. The breaches exposed an average of 28,500 records, an 8% increase from the previous year, and took 205 days to detect and contain, a 6% rise in response time.
The financial burden stems not just from the attacks themselves but from the cascading effects: business disruption, recovery efforts, legal obligations, and customer impact. Some companies even passed recovery costs to clients, while others, like Rogers, Fido, Telus Digital, Loblaw, Canada Computers, and Ardene, reported breaches in 2026.
Energy companies bore the highest average costs at $9.21 million per breach, followed by technology firms ($9.02 million) and industrial organizations ($8.89 million). IBM attributed the disparity to their complex networks, sensitive data, and low tolerance for downtime, making them prime targets for attackers.
The report highlighted AI as a critical tool in mitigating breaches. Organizations using AI extensively in security operations reported lower average costs ($5.5 million vs. $8.91 million) and faster response times 124 days to detect and 57 to contain breaches, compared to 154 and 71 days for non-AI adopters. However, 28% of attacks studied were believed to be AI-generated, underscoring the technology’s dual role in cybersecurity.
The study, conducted by the Ponemon Institute, analyzed 602 global organizations between March 2025 and February 2026, with follow-up interviews in May 2026. While the findings provide a snapshot of evolving threats, the methodology based on online surveys lacks a traditional margin of error due to non-random sampling.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2023
796
Breach
19 Jan 2023 • TELUS
Telus Corporation: Telus says it is investigating hack of its systems
Telus Cybersecurity Breach Investigation
745
CRITICAL-51
TEL1773347331
Telus Investigates Cybersecurity Breach Amid System Hack
Telus Corporation, one of Canada’s largest telecommunications providers, is actively investigating a hack of its systems, the company confirmed. The breach was disclosed amid growing concerns over cybersecurity threats targeting critical infrastructure.
While details remain limited, the incident highlights the ongoing risks faced by major corporations in safeguarding sensitive data. Telus, headquartered in Vancouver, has not yet released specifics on the scope of the breach, potential data exposure, or the methods used by attackers.
The investigation comes as cyber threats continue to escalate, with high-profile breaches affecting industries from healthcare to finance. No further information on the timeline or impact has been provided, but the company is likely working with cybersecurity experts to assess and mitigate the fallout.
As of now, Telus has not indicated whether customer or employee data was compromised, but the incident underscores the persistent challenges in defending against evolving cyber threats. Further updates are expected as the investigation progresses.
INCIDENT DETAILS -
TYPE
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for TELUS ??
What was TELUS's A.I Rankiteo Cyber Score in July 2026 ??
What was TELUS's A.I Rankiteo Cyber Score in June 2026 ??
What was TELUS's A.I Rankiteo Cyber Score in May 2026 ??
What was TELUS's A.I Rankiteo Cyber Score in April 2026 ??
What was TELUS's A.I Rankiteo Cyber Score in March 2026 ??
What was TELUS's A.I Rankiteo Cyber Score in February 2026 ??
What was TELUS's A.I Rankiteo Cyber Score in January 2026 ??
What was TELUS's A.I Rankiteo Cyber Score in December 2025 ??
What was TELUS's A.I Rankiteo Cyber Score in November 2025 ??
What was TELUS's A.I Rankiteo Cyber Score in October 2025 ??
What was TELUS's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on TELUS's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with TELUS ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view TELUS's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?