Almeida Law Group is investigating a data breach at TELUS International AI, Inc., d/b/a TELUS Digital. The breach occurred on October 18th, 2025 – March 2nd, 2026 and was discovered on June 30th, 2026. If you were affected, contact Almeida Law Group.
About TELUS International AI, Inc., d/b/a TELUS Digital
TELUS Digital is the digital services and business process outsourcing arm of Canadian telecommunications provider TELUS Corporation. It provides customer experience management, content moderation, AI data solutions, and cloud consulting to companies worldwide. The U.S. entity, TELUS International AI, Inc., is headquartered in Las Vegas, Nevada. The company rebranded from TELUS International to TELUS Digital in 2024. Because TELUS Digital processes outsourced operations for a wide range of clients, the personal information it holds can span many categories depending on the clients it serves.
What Happened?
TELUS International AI, Inc., d/b/a TELUS Digital was listed in a Texas Attorney General data security breach report (record BR-0005217). According to that filing, unauthorized access to company systems occurred between October 18th, 2025 and March 2nd, 2026, and was discovered on June 30th, 2026. A total of 39,766 individuals were affected. The compromised information included names, addresses, Social Security numbers, government-issued ID numbers (such as passports or state ID cards), and other unspecified information. TELUS Digital notified affected consumers by U.S. Mail and offered 12 months of TransUnion TrueIdentity credit monitoring. According to ClaimDepot, in a small number of cases the company has also stated that limited health information and financial account numbers may have been involved.
The threat actor group ShinyHunters claimed credit for the attack and, according to BleepingComputer, threatened to leak stolen data. TELUS Digital publicly confirmed the cybersecurity incident on March 12th, 2026, stating that unauthorized access had been limited to a select number of its systems and that business operations were not disrupted. ShinyHunters claimed to have stolen close to one petabyte of data; the company has not confirmed that volume, and it should be treated as an attacker-side allegation. Security researchers, as reported by Safestate and Breached.Company, have attributed the initial intrusion to credentials exposed in a prior Salesloft/Drift breach, though TELUS Digital has not officially confirmed that access vector. The breach was reported to the attorneys general in Texas, Vermont, and Washington.
TELUS Digital also experienced a separate, prior breach in 2023 in which its AI recruitment platform was compromised, exposing personal information for approximately 680,000 people worldwide and resulting in regulatory fines. That incident involved a different system and is not the same breach described in this filing.
Lawyers are currently investigating potential class action claims on behalf of individuals affected by this 2026 breach. No class action specific to this incident has been confirmed as filed as of the research date.
Key Facts at a Glance
- Company or Organization: TELUS International AI, Inc., d/b/a TELUS Digital
- Industry: Business Process Outsourcing / Digital Services / AI Data Solutions
- Location: Las Vegas, Nevada 89102
- Incident type: Unauthorized access to company systems
- Date of breach: October 18th, 2025 – March 2nd, 2026
- Date breach discovered: June 30th, 2026
- Date of consumer notification: July 31st, 2026 (published to Texas AG website)
- Total persons affected: 39,766
- Identity theft protection offered: 12 months of TransUnion TrueIdentity monitoring
- Prior breach: Yes — 2023 AI recruitment platform breach affecting approximately 680,000 people worldwide
- Litigation status: Class action investigation underway; no confirmed filing as of research date
- Source: Texas Attorney General Data Security Breach Report (BR-0005217); BleepingComputer; ClaimDepot; Safestate
What Should You Do?
If you received a notification letter from TELUS Digital, enroll in the 12-month TransUnion TrueIdentity monitoring offer before any deadline stated in your letter. Regardless of whether you enroll, consider placing a fraud alert or credit freeze with each of the three major credit bureaus — Equifax, Experian, and TransUnion — to reduce the risk of new accounts being opened in your name. Review your credit reports at AnnualCreditReport.com and watch your existing financial accounts closely for unfamiliar activity. Because Social Security numbers and government-issued ID numbers were among the compromised data types, the risk of identity theft may persist well beyond the monitoring period. If you believe your information has been misused, visit IdentityTheft.gov for step-by-step guidance from the Federal Trade Commission. If health information was involved in your particular case, also review your Explanation of Benefits statements and request copies of your medical records to check for inaccuracies.
Your Legal Rights
If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.