Skip to main content
Jump to a category page

Eight and a half months passed between the day TELUS Digital first detected unauthorized access to its systems and the day it told state regulators. In between, the hacking group ShinyHunters claimed it stole nearly a petabyte of data and demanded $65 million to keep it quiet.

TELUS International AI Inc., doing business as TELUS Digital, first identified unauthorized access to a limited number of its systems on November 12, 2025. The company did not confirm that the accessed documents contained personal information until March 18, 2026, and state regulatory filings in Texas and Washington did not appear until July 31, 2026, a delay chain totaling roughly eight and a half months from initial detection to state notice.

A ShinyHunters Extortion Demand, Not Just a Filing

This breach traces back to ShinyHunters, a hacking group that reportedly obtained Google Cloud Platform credentials through a separate breach of Salesloft, a sales software vendor, then used those stolen credentials to access TELUS Digital’s systems, according to BleepingComputer and TechRadar. ShinyHunters claims it stole close to a petabyte of data and demanded $65 million to withhold it from public release. TELUS has refused to pay. The attack pattern, a third party’s stolen credentials opening the door to a company’s own systems, raises real questions about how TELUS Digital managed vendor access to its network.

Who Is Affected?

This notice applies to people who participated in research studies through TELUS Digital or signed up to provide services to the company, its own contractors and research participants, not customers of the corporate clients TELUS Digital serves as a business process outsourcer.

What Information Was Exposed?

Per TELUS Digital’s own notice, exposed information includes:

  • Name and Contact Information
  • Date of Birth
  • Limited Health Information (a small number of individuals)
  • Financial Account Numbers (a small number of individuals)

How Many People Are Affected?

At least 9,968 people, per two independent state filings: 9,343 Washington residents and 625 Texas residents, both published July 31, 2026. TELUS Digital also disclosed the incident to the Vermont Attorney General. No national or global total has been released, and given the company’s size as a multinational AI-data and outsourcing firm, the true scope may be larger.

What Is TELUS Digital Offering?

TELUS Digital is offering complimentary cyber monitoring services designed to detect personal information on the dark web and alert affected individuals if it’s found. The company’s notice does not state how long this monitoring service will remain available.

Your Information Is at Risk

A name, date of birth, and contact information are already useful to an identity thief, and the individuals whose health information or financial account numbers were also exposed face a higher risk of targeted fraud. The eight-and-a-half-month gap between detection and disclosure means anyone affected went nearly a year without knowing they should be watching their accounts.

Do You Have Legal Options?

Companies that collect personal information from research participants and contract workers have a legal duty to safeguard that information and to notify affected individuals without unreasonable delay.

Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review if you received a notice from TELUS Digital.

FAQ

Who is affected by the TELUS Digital data breach?

People who participated in research studies through TELUS Digital or signed up to provide services to the company. This notice does not apply to customers of TELUS Digital’s corporate clients.

How many people were affected?

At least 9,968, per Texas and Washington state filings published July 31, 2026. No national total has been disclosed.

Why did it take so long to notify people?

TELUS Digital first detected the intrusion on November 12, 2025, but did not confirm personal information was involved until March 18, 2026, and did not file with state regulators until July 31, 2026, a roughly 8.5-month gap.

Do I have a legal claim?

Companies that collect personal information have a legal duty to protect it and to notify affected individuals within a reasonable time. If you received a notice from TELUS Digital, or believe your information was involved in this breach, contact the Data Breach Attorneys at Emery | Reddy at 206.207.8929 for a Free Case Review.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now