Back to blogCybersecurity

Telus: 700 TB Stolen by ShinyHunters and What It Changes

In March 2026, the ShinyHunters group claimed to have stolen 700 TB from Telus. Understand what happened and what your company needs to do right now.

Published onJune 30, 20265 min readMichelle Andrade
Share
Telus: 700 TB Stolen by ShinyHunters and What It Changes

When one of Canada's largest telecommunications carriers confirms that its systems have been compromised — and the responsible group publicly claims to have exfiltrated 700 terabytes of data, including proprietary source code and customers' personal information —, the market needs to stop and pay attention. Not out of curiosity. As a warning.

In March 2026, Telus, with more than 17 million subscribers and annual revenue exceeding CAD 20 billion, reported unauthorized access to its internal systems. The ShinyHunters group publicly claimed responsibility for the attack, alleging it obtained a volume of data that, in practice, is equivalent to an entire country's digital library.

Who Is ShinyHunters and Why It Matters

ShinyHunters is neither a new nor an unknown group. Active since at least 2020, the collective has amassed a track record that includes breaches against Tokopedia (91 million records), Wattpad, Microsoft, and AT&T — the latter considered one of the largest telecommunications data breaches in recent history, with more than 70 million records exposed. The group operates on a double-extortion model: it steals the data, threatens to publish it, and, in many cases, sells it on dark web forums regardless of whether a ransom is paid.

What makes the Telus case particularly serious is not just the announced volume — 700 TB is a figure that warrants analytical skepticism pending independent confirmation —, but the nature of the allegedly obtained data: source code from internal systems. When an attacker gains access to a telecommunications carrier's source code, they are not merely holding customer data. They potentially understand network architecture, internal authentication protocols, and integration points with partners and vendors.

The Supply Chain as a Risk Vector

Telecommunications is not an isolated sector. It is critical infrastructure upon which other industries operate. Banks authenticate via SMS through carrier networks. Hospitals depend on connectivity for digital health systems. Mid-sized companies use managed services that run through those same networks.

What the Telus incident clearly exposes is that supply chain risk in telecommunications is systemic. A breach at one carrier does not only affect its direct customers — it potentially compromises any organization that relies on its services for authentication, communication, or connectivity.

For Brazilian SMBs, the lesson is straightforward: the fact that you are not a Telus does not mean you are off the radar. ShinyHunters and similar groups monetize data at scale. Customer information, corporate credentials, and business partner data have market value regardless of the size of the target company.

The Role of Source Code in Attack Escalation

Source code exfiltration is frequently underestimated as a risk vector. In practice, it functions like a detailed building blueprint handed to a burglar. With access to a carrier's internal system code, a sophisticated group can identify undisclosed vulnerabilities, understand authentication flows, and, in more severe scenarios, build exploits targeting still-active infrastructure.

In terms of incident response, the presence of source code in a leak elevates the criticality level and demands a significantly longer remediation cycle — because the potential attack surface ceases to be known and becomes indeterminate.

What Companies Should Do Right Now

The Telus incident is not merely a Canadian problem. It is a case study with practical and immediate implications for any organization that manages sensitive data.

1. Two-Factor Authentication on All Exposed Systems

The majority of large-scale breaches begin with compromised credentials. 2FA is still the highest-return-per-effort security measure in corporate security. This applies especially to administrative panels, remote access (VPN, RDP), code repositories, and network monitoring systems. If any of these systems in your company still operates on username and password alone, you have a problem that can be fixed today.

2. Continuous Monitoring of Anomalous Traffic

Exfiltrating 700 TB of data is not a silent operation. Massive volumes of data leaving a network leave measurable traces — outbound traffic spikes, connections to uncatalogued IPs, unusual protocol usage. NDR (Network Detection and Response) tools, such as Darktrace, ExtraHop, or Vectra AI, exist precisely to identify these patterns before exfiltration is complete.

The problem is that many companies configure alerts but have no team or process to respond to them in real time. Having technology without a response process is the equivalent of installing a fire alarm without an evacuation plan.

3. Inventory and Segmentation of Critical Data

Do you know exactly where your source code is? Your most sensitive customer data? Which systems have access to what? In many mid-sized companies, the honest answer is "roughly." That needs to change. A data asset inventory — with sensitivity classification and granular access controls — is the prerequisite for any effective containment strategy.

Trust as a Regulatory Asset

In the context of the LGPD, an incident of the magnitude reported by Telus — even though it occurred in Canada — serves as a reference for what the ANPD (Autoridade Nacional de Proteção de Dados) considers a security failure with damage potential. Notification obligations, the demonstration of adequate technical measures, and civil liability for harm to data subjects are concrete realities for any company operating in Brazil.

Trust is not rebuilt in a sprint. When a telecommunications carrier has its source code stolen, the damage goes beyond the technical — it strikes the security perception of every customer, partner, and investor. For smaller companies, an equivalent incident can be definitive.

The Telus case is not a warning about Canada. It is a mirror.