ShinyHunters claims Brinks Home breach, threatens to leak stolen data

A Major Residential Security Company Falls Victim to a Sophisticated Hack

Residential security giant Brinks Home has recently disclosed that it was breached by hackers, who claim to have stolen sensitive data from its systems. The attackers, known as ShinyHunters, are threatening to release the allegedly stolen information online, putting the personal and financial details of millions of customers at risk.

According to reports, the breach occurred on July 13 when ShinyHunters carried out a Microsoft Entra voice phishing attack against Brinks Home employees. This type of social engineering exploit involves convincing an employee to complete a Microsoft authentication or registration process over the phone, resulting in the hacker gaining access to their account and subsequently breaching the company’s systems.

ShinyHunters claims to have stolen more than 4.9 million Salesforce records containing personally identifiable information (PII), including customer data from Brinks Home’s “Contacts” Object. Additionally, the group alleges that it has compromised over 3.8 million customer support chat logs and 4,000 rows of PII data associated with Brinks Home employees.

While Brinks Home has confirmed that the attacker is threatening to release the stolen information online, the company has not yet verified the accuracy of these claims. However, in an FAQ published on its website, Brinks Home warns customers that they may receive suspicious messages impersonating the company or other parties involved in the response. The company advises customers not to respond to such communications and to delete them instead.

This incident serves as a stark reminder of the importance of robust cybersecurity measures in today’s digital landscape. With millions of individuals’ sensitive data potentially at risk, it is essential for companies like Brinks Home to prioritize security and implement effective incident response procedures. It also highlights the growing threat posed by ShinyHunters, an extortion gang that has been linked to several high-profile breaches in recent months.

As a precautionary measure, Brinks Home customers should remain vigilant and be aware of any suspicious activity on their accounts. If you are affected by this breach, keep an eye out for phishing emails or messages claiming to be from Brinks Home or other parties involved in the response. Remember that legitimate companies will never ask you to click on links or provide sensitive information via email.

In light of this incident, it is essential for individuals and organizations alike to prioritize cybersecurity best practices, including regular security audits, employee training, and robust data protection measures. By doing so, we can minimize the risk of such breaches occurring in the first place and ensure that our sensitive data remains protected.


Source: Bleeping Computer — 2026-07-30