[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f36xvr8gawppeb":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":17,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":18,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":31,"seoTitle":32,"seoTitleEn":33,"seoDescription":32,"seoDescriptionEn":34,"logoUrl":35,"isVerified":4,"isSensitive":4,"isSpamList":36,"isMalware":36,"company":37},"6a6fa0c94a1c8eb6bc585d24","TELUSDigital2025","TELUS Digital Data Breach","telus-digital-2025","telusdigital.com","2025-10-18T00:00:00.000Z","2026-08-02T19:55:53.735Z","Unauthorized access to internal systems and acquisition of participant documents","https:\u002F\u002Fagportal-s3bucket.s3.amazonaws.com\u002Fdatabreach\u002FBreachA37809.pdf",[14,16],"https:\u002F\u002Foag.my.site.com\u002Fdatasecuritybreachreport\u002Fapex\u002FDataSecurityReportsPage",null,9968,"lower_bound","people","Low",[23,24,25,26,27,28,29,30],"Names","Contact information","Dates of birth","Physical addresses","Social security numbers","Government IDs","Medical information","Financial account information","\u003Cp>Documents associated with research and digital-service programs operated by TELUS International AI Inc. under the TELUS Digital brand were obtained by an unauthorized party in an October 2025 security incident. State notices confirm that the personal information of \u003Cstrong>at least 9,968 people\u003C\u002Fstrong> was affected.\u003C\u002Fp>\u003Cp>The scope concerns people who participated in TELUS Digital research studies or registered to provide services to the company. It does not mean that every TELUS telecommunications customer or every TELUS Digital user was affected.\u003C\u002Fp>\u003Ch2>Confirmed incident timeline\u003C\u002Fh2>\u003Cp>Regulator records identify October 18, 2025 as the incident date. TELUS Digital detected unauthorized access to a limited number of internal systems on November 12 and determined on March 18, 2026 that the obtained documents contained personal information belonging to some participants.\u003C\u002Fp>\u003Cp>In its April 17, 2026 notice, the company said it worked with cyber-forensics specialists and law enforcement and implemented additional security measures and employee training. It also reported no known misuse of personal information resulting from the incident.\u003C\u002Fp>\u003Ch2>How many people were affected?\u003C\u002Fh2>\u003Cp>The Washington filing reports 9,343 affected residents and the Texas filing reports 625. These separate state populations establish a verified lower bound of at least 9,968 people.\u003C\u002Fp>\u003Cp>The incident was also reported in Vermont, but no public resident count was provided, and no deduplicated nationwide total has been published. Therefore, 9,968 is not a final US total and the actual scope may be higher.\u003C\u002Fp>\u003Ch2>What information may have been affected?\u003C\u002Fh2>\u003Cp>The general scope may include names, contact information, and dates of birth. State records additionally identify addresses, Social Security numbers, and government-issued identifiers such as passport or state identification numbers.\u003C\u002Fp>\u003Cp>The company said limited health information and financial account numbers may also have been involved for a small number of people. Those fields should not be generalized to everyone affected; there is no verified statement that passwords or payment-card data were involved.\u003C\u002Fp>\u003Ch2>Identity and privacy risks\u003C\u002Fh2>\u003Cp>Social Security and government identification numbers can be used in new-account fraud, false identity verification, and tax fraud. The smaller group whose health or financial account information was involved faces additional privacy and financial risks.\u003C\u002Fp>\u003Cp>Names, contact details, and dates of birth can make messages about research invitations, service payments, or participant verification appear more credible. A message containing genuine program details is not proof that the sender is trustworthy.\u003C\u002Fp>\u003Ch2>Immediate protective steps\u003C\u002Fh2>\u003Cp>People who received notice should review reports from all three major credit bureaus and consider a free credit freeze or fraud alert based on their circumstances. New accounts, credit inquiries, address changes, and tax notices should be investigated promptly.\u003C\u002Fp>\u003Cp>Enroll in TELUS Digital’s complimentary monitoring service only through verified instructions in the personal letter or email. Financial-account activity and health-insurance statements should also be reviewed for unfamiliar changes.\u003C\u002Fp>\u003Ch2>Protection from targeted scams\u003C\u002Fh2>\u003Cp>Do not respond to messages that use a research payment, participant-profile update, or identity check as a reason to request a password, one-time code, new copy of an identity document, or money. Use a known official channel instead of following an unexpected link.\u003C\u002Fp>\u003Cp>A personal notice is the primary source for individual data scope. Although no misuse has been reported, persistent identity numbers warrant long-term credit and account monitoring; suspected misuse should be reported to the relevant institution and authorities through IdentityTheft.gov.\u003C\u002Fp>","","TELUS Digital Data Breach (At Least 9,968 People Affected)","TELUS Digital incident affected at least 9,968 people and involved identity, contact, birth-date, and limited health or financial information.","https:\u002F\u002Fimages.ctfassets.net\u002F3viuren4us1n\u002F6iSn8WFIZQsi4AqMK0LykE\u002F43e86bc5ab0474696a0a010de41f4c8b\u002FTELUS_Digital.jpg",false,{"name":38,"sector":39,"country":40,"website":10,"websiteArchiveUrl":32,"websiteStatus":41,"websiteCheckedAt":12},"TELUS Digital","Technology","United States","active"]