惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

人人都是产品经理
人人都是产品经理
宝玉的分享
宝玉的分享
小众软件
小众软件
有赞技术团队
有赞技术团队
月光博客
月光博客
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
MyScale Blog
MyScale Blog
Engineering at Meta
Engineering at Meta
Stack Overflow Blog
Stack Overflow Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
N
Netflix TechBlog - Medium
D
Docker
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
MongoDB | Blog
MongoDB | Blog
WordPress大学
WordPress大学
J
Java Code Geeks
罗磊的独立博客
V
Visual Studio Blog
雷峰网
雷峰网
H
Help Net Security
T
The Blog of Author Tim Ferriss
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
大猫的无限游戏
大猫的无限游戏
F
Fortinet All Blogs

Consumer Insights

Weverse data breach affects 422,584 user accounts Manchester Airports Group cyberattack exposes data of 8.7 million customers Sakura Internet hack may affect 1.36 million accounts French tax authority breach exposes data of 678,000 people and businesses Phone number leaked in the Bloctel breach? Here’s what to do. SplitVPN breach reveals 58 million hidden connection logs South Korea diplomatic academy hack exposes diplomat data Credential stuffing attack at Chick-fil-A comes with data breach notice for customers Coca-Cola halts Fairlife production across US after ransomware attack Qantas data breach started with a fake IT support call Lidl warns customers after data breach How to find out if your identity has been exposed by infostealers Texas breach exposes PII of 3 million hunting and fishing license customers Maine forced to take down data breach portal after fake notices filed with authorities Carnival breach exposes data of nearly 6 million people 7-Eleven data breach exposes data of 185,000 people UK Water Supplier Fined Nearly £1 Million After Hackers Roamed Networks for Almost 2 Years DAEMON Tools Lite breach prompts urgent update after malware-laced installer Instructure confirms breach; millions of Canvas users potentially impacted Stalkerware data leak exposes private screenshots linked to celebrities and influencers Hackers claim to have breached Udemy, stealing 1.4 million user records Rituals data breach exposes customer details Booking.com says breach exposed travelers’ data Basic-Fit data breach exposes member information across Europe Rockstar Games confirms breach after ShinyHunters leaks stolen analytics data Lapsus$ claims AstraZeneca breach exposes code and credentials Aura data breach exposes 900,000 records after phishing attack Was Your Data Exposed in the Latest Under Armour Breach? Here’s What You Should Do Breach at Tinder, Hinge and OkCupid exposes user data Europe Fines Big Tech €1.2 Billion under GDPR in 2025
Telus Digital data breach confirmed after ShinyHunters cl...
Vlad CONSTANTINESCU · 2026-03-13 · via Consumer Insights

Telus Digital is probing a confirmed breach as ShinyHunters  claims petabyte-scale data theft tied to compromised cloud credentials.

Telus Digital confirms breach and launches investigation

Telus Digital says it is investigating a cybercrime involving unauthorized access to a limited number of systems after a threat actor claimed it stole nearly 1 petabyte of data.

The company said operations remain fully functional and it has brought in external forensics support and police, adding it will notify affected customers as the investigation progresses.

Why BPO breaches can ripple across multiple brands

As a business process outsourcing (BPO) vendor, Telus Digital supports customer service, content operations and AI-related workflows for external clients, a position that can aggregate sensitive data in one place.

That concentration is why BPO incidents often run a “blast radius” risk. A single compromise can expose customer support artifacts, internal tooling clues and downstream authentication pathways of multiple organizations.

ShinyHunters points to cloud credentials

ShinyHunters claims it gained access using Google Cloud credentials found in data leaked from the Salesloft Drift ecosystem, then pivoted into additional environments after finding more secrets.

Google’s threat intelligence reporting has already warned that Drift/Salesloft-related compromises can enable follow-on intrusions when stolen tokens, credentials or support-case data are reused across platforms.

What data may be exposed and what customers should verify

The attackers allege the haul includes client BPO datasets, such as support operations, moderation workflows, and performance metrics, as well as source codes, financial information, FBI background checks, call records and recordings tied to telecom services. These claims are not yet independently verified.

For affected customers, the immediate hygiene checklist is familiar:

  • Rotate cloud and SaaS secrets
  • Review BigQuery/Cloud audit logs
  • Validate SSO session integrity
  • Hunt for “credential-in-data” exposure patterns ShinyHunters is known to exploit