Telus Digital, the digital services and business process outsourcing (BPO) division of Canadian telecommunications provider Telus, recently confirmed that it suffered a major security breach, following hackers’ claims that nearly 1 petabyte of data. Telus Digital provides customer support, content curation, artificial intelligence data services and other BPO functions globally, making the organization an attractive target for high-impact attacks.

The strategic targeting of BPO providers
BPOs handle customer support, billing and internal authentication tools for multiple companies at once. This makes them easy targets for hacker groups seeking access to vast amounts of data in a single breach. Telus Digital, due to the breadth of its services and the systems it manages, was at the center of a months-long attack that compromised the information of millions of users.
See also: Contagious Interview: The technique of North Korea's fake IT workers
The ShinyHunters Attack
The hackers who allegedly carried out the breach are known as ShinyHunters, a group with a history of extortion and data theft from numerous companies worldwide. They claim to have seized customer data, call logs and operational records from Telus divisions, including consumer telecommunications services and BPO support.
Telus Digital's reaction
Telus Digital said that once the unauthorized access was discovered, immediate steps were taken to secure systems without any disruption to customer service. The company has hired cybersecurity experts and is working with authorities to assess the extent of the breach and notify affected customers.

Methods of violation and blackmail
According to the hackers themselves, ShinyHunters used Google Cloud credentials stolen from a previous breach of the Salesloft Drift. These credentials allowed them to gain access to Telus corporate systems, including BigQuery and other sensitive environments. Using tools like trufflehog, the team searched for additional passwords and secrets to expand the breach.
See also: Iranian hackers claim responsibility for wiper attack on Stryker
The scope of stolen data
ShinyHunters claims to have obtained nearly 1 petabyte of data, including customer information, source code, Salesforce data, voice call recordings, and security audits. The data relates to BPO business functions such as employee evaluations, AI-powered support, fraud detection, and content moderation. In addition, call logs and voice recordings from consumer telecommunications services appear to have been exposed, including detailed metadata.
Global impact and previous attacks
ShinyHunters has a history of breaching major companies such as Google, Cisco, Match Group, and PornHub. The group now frequently targets SaaS cloud, exploiting credentials and SSO accounts to access platforms such as Microsoft 365, Google Workspace, Salesforce, Slack, and Dropbox. Their techniques include voice phishing, multifactor authentication code theft, and password exploitation.

Conclusions and next steps
The Telus Digital breach highlights the continued vulnerability of BPO companies and the need for robust cybersecurity measures, particularly for cloud platforms and customer data management. Telus is continuing to investigate the extent of the theft, while the ShinyHunters group appears determined to extort money from the company, highlighting the dangers of modern cyberattacks.
See also: UNC6426: Exploited nx npm supply chain for AWS admin access
Telus Digital says customer security remains a priority, and collaboration with experts and law enforcement continues, seeking to prevent future intrusions and limit the impact of the massive breach.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
