ShinyHunters claims Brinks Home breach, threatens to leak stolen data

A major residential security company, Brinks Home, has been breached by hackers from the notorious ShinyHunters extortion gang. The attackers claim to have stolen over 4.9 million records containing personally identifiable information (PII) from Salesforce, and are threatening to leak this data unless Brinks Home pays them off.

The breach is significant not just because of the scale of the attack, but also because it highlights the ongoing threat posed by social engineering tactics like voice phishing. ShinyHunters allegedly breached Brinks Home’s systems on July 13 through a Microsoft Entra voice phishing (vishing) attack, which involves tricking employees into divulging sensitive information over the phone.

According to the attackers, they exfiltrated more than 1.1 million rows of customer data from the “Contacts” Salesforce Object, as well as PII associated with Brinks Home employees and 3.8 million customer support chat logs. While Bleeping Computer has not been able to verify the accuracy of these claims, Brinks Home has confirmed that it is investigating the incident and that the attackers have threatened to release the allegedly stolen data.

The breach raises concerns about the security measures in place at Brinks Home, particularly when it comes to protecting sensitive customer information. As a residential security company, Brinks Home should be held to high standards of data protection, especially given its large customer base and significant revenue generation. The fact that ShinyHunters was able to breach its systems through a social engineering attack is particularly worrying.

For customers of Brinks Home, the incident serves as a reminder to remain vigilant about potential phishing attacks and other forms of social engineering. Brinks Home has warned that threat actors may exploit the incident by sending fraudulent messages impersonating the company or other parties involved in the response. Customers are advised not to respond to suspicious communication or click on any links, but rather delete the message.

The ShinyHunters breach also highlights the ongoing problem of data breaches and extortion gangs preying on companies that have been compromised. It is essential for organizations to invest in robust security measures, including regular penetration testing and incident response planning, to mitigate the risk of such attacks.

As a cybersecurity-aware reader, it’s essential to take note of this breach and be cautious about potential phishing attacks. When dealing with sensitive information or receiving emails from companies like Brinks Home, always verify the authenticity of the communication before taking any action. By being vigilant and proactive in protecting our personal data, we can reduce the risk of falling victim to such attacks.


Source: Bleeping Computer — 2026-07-30