ShinyHunters Hits Brinks Home With a Phone Call
Brinks Home, the US home security company serving over one million customers, confirmed on Bleeping Computer that attackers accessed its systems and are threatening to publish the stolen data.
The attackers got in on July 13 through a vishing (voice phishing — a social engineering attack where a hacker calls an employee and tricks them into completing a fake login or authentication process) attack targeting Microsoft Entra, the company's identity management system. By the time Brinks Home identified the intrusion on July 20, the group had already been inside.
The group behind it is ShinyHunters, a well-known extortion gang. They claim to have taken 4.9 million Salesforce records containing customer personal information, over 4,000 rows of employee PII including names, emails, and job titles, and 3.8 million customer support chat logs.
Brinks Home has confirmed the threat to publish is real, but has not yet verified exactly what data was taken or who is affected. The company has promised direct notification if your information is confirmed as part of the breach.
One immediate concern: attackers often follow a breach like this with impersonation scams. Fake messages pretending to be Brinks Home are already a risk.
What to do: If you are a Brinks Home customer, do not click links or respond to unsolicited messages claiming to be from the company. Go directly to brinkshome.com for updates. Consider placing a fraud alert with the major credit bureaus as a precaution.
Sources

