Telus Digital confirmed in mid March 2026 that intruders had accessed internal systems, an intrusion the extortion group ShinyHunters publicly claimed.1 Cybersecurity Dive 2026-03-16 Telus Digital confirmed the intrusion, did not identify what was taken, and ShinyHunters claimed up to one petabyte. Open source ShinyHunters asserted it had exfiltrated between 700 terabytes and roughly one petabyte of data, a volume the reporting describes as not yet independently verified, spanning customer support recordings, proprietary source code, employee records and even FBI background check results.2 Hackread 2026-03-16 ShinyHunters claimed 700 terabytes to one petabyte including support recordings, source code and FBI background check results. Open source The entry point was not a novel exploit of Telus Digital itself. Attackers used Google Cloud credentials found in data leaked from the Salesloft Drift ecosystem, then pivoted inward.3 Bitdefender HotForSecurity 2026-03-13 Attackers used Google Cloud credentials from the Salesloft Drift leak to pivot into Telus Digital, which said operations remained functional. Open source The stake is the pattern, not the petabyte. We assess with high confidence that credential reuse across cascading breaches, rather than any single zero day, is now the dominant mechanism of large scale corporate data theft, and that this raises the downstream cost of every prior breach.

The number is loud, the method is louder

A claimed petabyte is a headline figure, and it deserves the skepticism the reporting itself applies: Telus Digital did not identify what was taken, its investigation is ongoing, and the volume rests on the attacker's own claim.1 Cybersecurity Dive 2026-03-16 Telus Digital confirmed the intrusion, did not identify what was taken, and ShinyHunters claimed up to one petabyte. Open source Treat the size as an unverified assertion by a party with an incentive to inflate it. What is better grounded is the composition. Samples shared with reporters showed personally identifiable information, call center recordings from business customers, source code and background check data, a mix consistent with a business process outsourcing provider that handles other companies' operations and their customers' interactions.1 Cybersecurity Dive 2026-03-16 Telus Digital confirmed the intrusion, did not identify what was taken, and ShinyHunters claimed up to one petabyte. Open source

The mechanism is the part worth studying. ShinyHunters did not pick the lock at Telus Digital. It walked in with a key found lying in the wreckage of an earlier compromise, cloud credentials exposed through the Salesloft Drift leak, and then used discovered secrets to move into further environments.3 Bitdefender HotForSecurity 2026-03-13 Attackers used Google Cloud credentials from the Salesloft Drift leak to pivot into Telus Digital, which said operations remained functional. Open source This is not an isolated trick. It is the same supply chain logic that let the group scan and drain misconfigured software as a service portals across 2026.2 Hackread 2026-03-16 ShinyHunters claimed 700 terabytes to one petabyte including support recordings, source code and FBI background check results. Open source

Why the reuse chain is the durable threat

The single most important fact in this incident is that the breach of one vendor became the breach of another. Credentials that leaked from Salesloft became the doorway into Telus Digital.3 Bitdefender HotForSecurity 2026-03-13 Attackers used Google Cloud credentials from the Salesloft Drift leak to pivot into Telus Digital, which said operations remained functional. Open source That converts every historical breach into a live liability, because dumped secrets do not expire on their own; they sit in criminal inventories until someone tries them against a fresh target. We assess with high confidence that this compounding effect is structural, because it rests on documented tradecraft rather than on a one time lucky find.

For a BPO provider the blast radius is wider than for a typical company. Telus Digital runs support operations, moderation workflows and performance analytics for other businesses, so a compromise of its systems reaches those clients' data as well as its own.3 Bitdefender HotForSecurity 2026-03-13 Attackers used Google Cloud credentials from the Salesloft Drift leak to pivot into Telus Digital, which said operations remained functional. Open source A source code plus call data haul, if the claims hold, hands an adversary both the recordings that fuel targeted fraud and the software internals that help find the next vulnerability.2 Hackread 2026-03-16 ShinyHunters claimed 700 terabytes to one petabyte including support recordings, source code and FBI background check results. Open source

Who gains and who loses

The immediate loser is Telus Digital, which faces notification obligations, forensic costs and reputational damage even though it says core operations remained functional.3 Bitdefender HotForSecurity 2026-03-13 Attackers used Google Cloud credentials from the Salesloft Drift leak to pivot into Telus Digital, which said operations remained functional. Open source The larger set of losers are its enterprise clients, whose customers' recordings and records may have been swept up through a vendor they do not directly control. Any organization that shared data with the affected environment now inherits fraud and phishing risk it did not create.

ShinyHunters gains a reinforced business model. Each successful reuse of stolen credentials validates the strategy of treating old breaches as feedstock for new ones, and lowers the effort needed for the next operation.2 Hackread 2026-03-16 ShinyHunters claimed 700 terabytes to one petabyte including support recordings, source code and FBI background check results. Open source Identity and cloud security vendors gain demand, because the practical defenses here are credential rotation, scoped permissions and continuous log auditing, exactly the controls a compromised customer is told to implement after the fact.3 Bitdefender HotForSecurity 2026-03-13 Attackers used Google Cloud credentials from the Salesloft Drift leak to pivot into Telus Digital, which said operations remained functional. Open source The uncomfortable winner is anyone selling the cleanup, because the reuse chain guarantees a steady pipeline of victims.

The counter-case

The thesis could be overstated in two ways. First, the petabyte claim may collapse under investigation, and if the real exfiltration proves modest, the incident becomes a serious but ordinary breach rather than a marker of an industrialized model.1 Cybersecurity Dive 2026-03-16 Telus Digital confirmed the intrusion, did not identify what was taken, and ShinyHunters claimed up to one petabyte. Open source Second, credential reuse is not new; attackers have chained leaks for years, so calling it the dominant mechanism could be reading a trend into a familiar tactic. For the assessment to be wrong, this would need to be a contained event with limited downstream reuse, and the broader 2026 pattern of ShinyHunters activity would have to be coincidence rather than method. The weight of evidence, a documented Salesloft to Telus pivot plus a run of similar portal driven thefts, argues against that reading, which is why the confidence stays high on the mechanism even while the volume stays unverified.

What to watch

  • Telus Digital confirms or refutes the volume. If the company or independent forensics publish a concrete figure within one to two quarters, the petabyte claim resolves; a persistent refusal to quantify keeps it an attacker assertion.1 Cybersecurity Dive 2026-03-16 Telus Digital confirmed the intrusion, did not identify what was taken, and ShinyHunters claimed up to one petabyte. Open source
  • Downstream victims surface. Watch for enterprise clients of Telus Digital disclosing their own exposures over the next six months; each one confirms the BPO blast radius thesis.3 Bitdefender HotForSecurity 2026-03-13 Attackers used Google Cloud credentials from the Salesloft Drift leak to pivot into Telus Digital, which said operations remained functional. Open source
  • Fraud tied to the recordings appears. If targeted phishing or vishing campaigns using the stolen call data emerge within the year, the practical harm from the haul moves from theoretical to measured.2 Hackread 2026-03-16 ShinyHunters claimed 700 terabytes to one petabyte including support recordings, source code and FBI background check results. Open source
  • More Salesloft derived intrusions land. If additional companies are breached via credentials from the same Salesloft leak, the reuse chain graduates from pattern to campaign, and every prior breach victim should treat their old exposure as an active threat.3 Bitdefender HotForSecurity 2026-03-13 Attackers used Google Cloud credentials from the Salesloft Drift leak to pivot into Telus Digital, which said operations remained functional. Open source

The forward implication is blunt: in a world where stolen keys never rust, breach response is no longer a one time event but a standing obligation to rotate, scope and watch, indefinitely.