ShinyHunters Claims Brinks Home Data Breach, Threatens Public Data Leak
Residential security provider Brinks Home has confirmed a data breach after the ShinyHunters threat group claimed responsibility and threatened to leak stolen customer and employee information.

Residential security company Brinks Home has disclosed that hackers breached some of its systems and are threatening to leak allegedly stolen data. The company identified the attack on July 20 and immediately activated its incident response procedure to contain the breach. William Niles, CEO at Brinks Home, stated that the company’s team was working with “leading forensics experts to address this issue.”
The intrusion did not impact the company’s alarm monitoring and system functionality. At the beginning of the week, the ShinyHunters extortion gang claimed responsibility for the attack, alleging that they stole more than 4.9 million Salesforce records containing personally identifiable information (PII).
Brinks Home, which generates approximately $830 million in annual revenue and serves over 1 million customers, confirmed the breach. In a conversation with BleepingComputer, ShinyHunters detailed their method, stating they breached Brinks Home on July 13 through a Microsoft Entra voice phishing (vishing) attack. This social engineering tactic involves tricking an employee into completing a Microsoft Entra authentication process, thereby granting the attacker access to the victim's account.
According to the threat actor, they exfiltrated over 1.1 million rows of customer data from the "Contacts" Salesforce Object. Additionally, ShinyHunters claimed to have stolen over 4,000 rows of PII data associated with Brinks Home employees, including full names, email addresses, job titles, and phone numbers. The group also asserted they obtained more than 3.8 million customer support chat logs from the Brinks Care Cresta instance.
While BleepingComputer has not independently verified the accuracy of ShinyHunters' claims, Brinks Home has confirmed that the attacker “has threatened to release information it claims to have taken” and that “such material may be posted publicly.” The company is currently investigating to determine the exact nature and ownership of the compromised information.
In an FAQ for the incident, Brinks Home stated that affected customers would be notified and advised on necessary steps. The company is also warning customers about potential phishing attempts impersonating Brinks Home or other involved parties. Individuals are urged to be cautious of suspicious communications, avoid clicking on links, and delete any unsolicited messages.
This incident underscores the persistent risks faced by security service providers and the sensitive data they hold. The use of vishing attacks to compromise cloud-based authentication systems like Microsoft Entra highlights an evolving tactic by threat actors seeking to gain initial access to corporate networks.
The Register Security article provides additional context on the Brinks Home breach, noting that the threat actor, ShinyHunters, has a history of targeting Salesforce instances and has claimed to have stolen over 4.9 million records containing PII. It also highlights Brinks Home's separation from the larger Brinks brand and its parent company's financial difficulties, adding a layer of concern regarding the company's overall stability and security posture.
The new article confirms that Brinks Home detected the intrusion on July 20, indicating approximately a week of attacker dwell time before containment. It also details the specific data types compromised, including customer contact information, employee PII, and customer support chat logs, totaling nearly five million records, though Brinks Home has not yet confirmed the exact scope and affected individuals. The report further elaborates on the broader pattern of ShinyHunters targeting Salesforce environments via social engineering, noting that stolen chat logs can be particularly dangerous for follow-up phishing.
The extortion group ShinyHunters has claimed responsibility for the attack and has begun leaking over 41 gigabytes of data allegedly stolen from Brinks Home. The group states that more than 4.9 million records, including personally identifiable information, were exfiltrated from the company's Salesforce instance. Brinks Home has not confirmed the specifics of the threat actor but noted that alarm monitoring and system functionality remain unaffected.