Brinks Home Confirms Data Breach After ShinyHunters Claim
Key Takeaways Brinks Home, a major residential security provider, has confirmed a data breach following claims by the ShinyHunters extortion group. The breach involves approximately 4.9 million...
Key Takeaways
- Brinks Home, a major residential security provider, has confirmed a data breach following claims by the ShinyHunters extortion group.
- The breach involves approximately 4.9 million records, including customer data from Salesforce and employee PII, but the exact scope is still under investigation.
- The compromised systems are related to Salesforce and customer support, not Brinks Home’s core security products or alarm monitoring services.
- This incident aligns with previous ShinyHunters campaigns targeting Salesforce environments via social engineering.
Brinks Home, a leading provider of residential security solutions across North America, has officially acknowledged a security breach within its IT infrastructure. This confirmation follows claims by the notorious ShinyHunters cybercriminal group, which asserted responsibility for illicitly obtaining nearly five million records from the company’s Salesforce environment.
Table Of Content
The acknowledgment came after ShinyHunters listed “BH Security, LLC (brinkshome.com)” on their dark web leak site. The group issued an ultimatum, threatening to release the exfiltrated data unless Brinks Home paid a ransom by July 30, 2026.
Brinks Home stated that it detected unauthorized access to its systems on July 20. The company swiftly initiated its incident response protocols to contain the intrusion. This timeline indicates that the attackers had approximately one week of dwell time within the systems before the breach was successfully contained.
Brinks Home Confirms Data Breach
ShinyHunters alleges to have stolen over 1.1 million rows of customer data from the Salesforce “Contacts” object. Additionally, the group claims to possess more than 4,000 rows of employee Personally Identifiable Information (PII), encompassing names, email addresses, job titles, and phone numbers. The exfiltrated data also reportedly includes approximately 3.8 million customer support chat logs from the Brinks Care Cresta platform.
These figures collectively account for the 4.9 million records advertised on the ShinyHunters leak site. However, cybersecurity researchers have noted that this headline number represents a sum of various record types and chat transcripts, rather than a distinct count of unique affected customers.
Brinks Home has clarified that it is still in the process of definitively confirming the precise nature of the compromised information and the specific individuals whose data may have been affected.
Crucially, Brinks Home has emphasized that its core security products and services remain unaffected by this incident. Customer alarm monitoring and system functionalities continue to operate without interruption, as the compromised systems were linked to Salesforce and support infrastructure, rather than the company’s security hardware or monitoring network itself.
ShinyHunters’ Broader Campaign
This incident fits within a broader pattern of Salesforce-focused vishing campaigns attributed to ShinyHunters throughout 2026. Previous organizations targeted by the group, utilizing similar social engineering tactics against Single Sign-On (SSO) providers like Microsoft Entra and Okta, include Cushman & Wakefield, Kodak, and Sysco.
Security experts caution that the theft of customer support transcripts poses a significant risk. Such data often contains sensitive details like service addresses, equipment specifics, and account histories, which can be leveraged to craft highly credible and dangerous follow-up phishing attempts.
Brinks Home has urged its customers to exercise heightened vigilance against unsolicited emails, text messages, or phone calls that request personal information or login credentials. The company explicitly states that it will never ask for sensitive data through unsolicited communications.
Should it be confirmed that personal information has been compromised, Brinks Home has committed to notifying affected individuals in accordance with applicable legal requirements and will provide any necessary recommended next steps.
What You Should Do
- Be extremely cautious of any unsolicited communications, including emails, texts, or phone calls, claiming to be from Brinks Home.
- Do not click on links or respond to suspicious messages that reference the breach or ask for personal or account information.
- Always verify the authenticity of any communication by contacting Brinks Home directly through official channels, such as their official website or customer service numbers, rather than relying on contact details provided in unsolicited messages.
- Implement strong, unique passwords for all online accounts and enable multi-factor authentication (MFA) wherever possible.
- Monitor your financial statements and credit reports for any suspicious activity.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.