VYPR
breachPublished Jul 30, 2026· 1 source

ShinyHunters Claims Brinks Home Data Breach, Threatens Public Data Leak

Residential security provider Brinks Home has confirmed a data breach after the ShinyHunters threat group claimed responsibility and threatened to leak stolen customer and employee information.

Residential security company Brinks Home has disclosed that hackers breached some of its systems and are threatening to leak allegedly stolen data. The company identified the attack on July 20 and immediately activated its incident response procedure to contain the breach. William Niles, CEO at Brinks Home, stated that the company’s team was working with “leading forensics experts to address this issue.”

The intrusion did not impact the company’s alarm monitoring and system functionality. At the beginning of the week, the ShinyHunters extortion gang claimed responsibility for the attack, alleging that they stole more than 4.9 million Salesforce records containing personally identifiable information (PII).

Brinks Home, which generates approximately $830 million in annual revenue and serves over 1 million customers, confirmed the breach. In a conversation with BleepingComputer, ShinyHunters detailed their method, stating they breached Brinks Home on July 13 through a Microsoft Entra voice phishing (vishing) attack. This social engineering tactic involves tricking an employee into completing a Microsoft Entra authentication process, thereby granting the attacker access to the victim's account.

According to the threat actor, they exfiltrated over 1.1 million rows of customer data from the "Contacts" Salesforce Object. Additionally, ShinyHunters claimed to have stolen over 4,000 rows of PII data associated with Brinks Home employees, including full names, email addresses, job titles, and phone numbers. The group also asserted they obtained more than 3.8 million customer support chat logs from the Brinks Care Cresta instance.

While BleepingComputer has not independently verified the accuracy of ShinyHunters' claims, Brinks Home has confirmed that the attacker “has threatened to release information it claims to have taken” and that “such material may be posted publicly.” The company is currently investigating to determine the exact nature and ownership of the compromised information.

In an FAQ for the incident, Brinks Home stated that affected customers would be notified and advised on necessary steps. The company is also warning customers about potential phishing attempts impersonating Brinks Home or other involved parties. Individuals are urged to be cautious of suspicious communications, avoid clicking on links, and delete any unsolicited messages.

This incident underscores the persistent risks faced by security service providers and the sensitive data they hold. The use of vishing attacks to compromise cloud-based authentication systems like Microsoft Entra highlights an evolving tactic by threat actors seeking to gain initial access to corporate networks.

Synthesized by Vypr AI