Brinks Home Security Breached: ShinyHunters Claims Millions of Records Stolen via Vishing Attack
Residential security giant **Brinks Home** has confirmed a recent data breach, with the notorious **ShinyHunters** extortion group claiming responsibility. The attackers allege they exfiltrated over 4.9 million **Salesforce** records, including personally identifiable information (PII) and employee data, through a sophisticated voice phishing (vishing) attack targeting **Microsoft Entra**.
Residential security provider **Brinks Home** has disclosed that its systems were compromised by hackers, who are now threatening to leak allegedly stolen data.
The company identified the breach on July 20 and immediately initiated its incident response protocols to contain the intrusion. **William Niles**, CEO at **Brinks Home**, stated that the company's team is collaborating with βleading forensics experts to address this issue.β
Crucially, **Brinks Home** confirmed that its core alarm monitoring and system functionality were not impacted by the security incident.
### ShinyHunters Claims Responsibility
Earlier this week, the **ShinyHunters** extortion gang publicly claimed the attack on **Brinks Home**. They allege to have stolen more than 4.9 million **Salesforce** records containing sensitive personally identifiable information (PII).

**Brinks Home**, a significant player in the home security market, serves over 1 million customers across the United States, Canada, and Puerto Rico, generating approximately $830 million in annual revenue.
### Vishing Attack on Microsoft Entra
In a conversation with BleepingComputer, **ShinyHunters** detailed their method, stating they breached **Brinks Home** on July 13 via a **Microsoft Entra** voice phishing (vishing) attack. This social engineering tactic involves threat actors calling employees and manipulating them into completing a **Microsoft Entra** authentication or registration process, thereby gaining access to their accounts.
The threat actor claims to have exfiltrated over 1.1 million rows of customer data from the "Contacts" **Salesforce** Object. Additionally, **ShinyHunters** asserts they stole more than 4,000 rows of PII belonging to **Brinks Home** employees, including full names, email addresses, job titles, and phone numbers. The group also claims to have acquired over 3.8 million customer support chat logs from the **Brinks Care Cresta** instance.
While the alleged data has not been independently verified, **Brinks Home** has confirmed that the attacker βhas threatened to release information it claims to have takenβ and that βsuch material may be posted publicly.β
### Company Response and Customer Advisory
In its latest updates and an FAQ section regarding the incident, **Brinks Home** stated that it is actively investigating and has βnot yet confirmed exactly what information was involved or whose.β The company assures customers that if their information is determined to be affected, they will be notified with appropriate steps to take.
**Brinks Home** is also cautioning customers about potential follow-up exploitation, warning that threat actors may send fraudulent messages impersonating the company or other parties involved in the incident response. Customers are advised to exercise extreme caution, refrain from responding to suspicious communications, and avoid clicking on any links in such messages.