Canada's second-largest telecom TELUS is investigating a potential data breach after a hacker put up private GitHub repositories and payroll records for sale
a threat actor shared samples online of what appears to be employee data. They subsequently posted screenshots that apparently show private source code repositories & payroll records held by the company. … Tweets: Ax Sharma / @ax_sharma : TELUS, Canada's second-largest telco, is investigating a potential #databreach after sample sets of company's employee data, payroll records, and private GitHub repos appeared on a data breach forum this week. https://www.bleepingcomputer.com/ ...
Context & Ripple Effects
The listing follows a familiar script: a threat actor posts samples on a breach forum to prove access, then puts the full trove up for sale — the same playbook that preceded T-Mobile confirming hackers had reached its systems with subscriber data on sale in 2021. Weeks earlier, Okta disclosed that attackers had stolen its source code straight out of its GitHub repositories, though without touching customer data.
What distinguishes the TELUS case is the bundle: private repositories plus payroll and employee records together suggest deep internal access rather than a scraped database, which is why Canada's second-largest telco is treating it as an active investigation rather than a confirmed dump.
First-order effects
- TELUS employees whose payroll and personal data appear in the samples are immediately exposed, and the company must verify authenticity while deciding whether the repos for sale are genuine internal code.
Second-order effects
- If the source code proves real, buyers gain reconnaissance material on TELUS's internal systems, raising the odds of follow-on intrusion attempts — the escalation path Okta faced after its own GitHub repositories were hacked in December.
Third-order effects
- Telecoms are becoming repeat premium targets because one compromise yields both customer-facing services and rich HR/payroll data; expect boards at carriers like TELUS to treat code-repository hygiene and vendor-side incidents like the one later claimed against Telus Digital by ShinyHunters as standing board-level risk items.
The trend: Breach forums are shifting from selling customer databases to auctioning combined source-code-and-employee-data troves from critical infrastructure operators.