Skip to content
Social engineeringContained

Brinks Home Salesforce data theft via Entra vishing (ShinyHunters)

U.S. home security provider Brinks Home confirmed a cybersecurity incident after ShinyHunters claimed it stole 4.9 million Salesforce records and support chat logs through a Microsoft Entra voice-phishing call.

Victim
Brinks Home
records
4.9M
users
732.2K

On 27 July 2026, the extortion group ShinyHunters listed Brinks Home, a U.S. residential security and alarm-monitoring provider serving more than one million people across North America, on its data-leak site. The group claimed to have stolen 4.9 million records from the company's Salesforce environment and threatened to publish them unless Brinks Home made contact by 30 July. Brinks Home confirmed it was investigating a corporate cybersecurity incident that it had detected on 20 July.

ShinyHunters said it got in on 13 July through a Microsoft Entra voice-phishing (vishing) call, in which a caller walks an employee through what looks like a routine authentication or registration step and ends up controlling the account. The company said its core security products and alarm monitoring services were not affected.

What was taken

The group claimed more than 1.1 million customer contact rows from Salesforce, over 4,000 rows of employee data (names, emails, job titles and phone numbers) and roughly 3.8 million customer support chat logs from the company's Cresta-based support platform, about 41 GB in total. Brinks Home initially said it had not yet confirmed exactly what information was involved and would notify affected individuals as required. The data was later published, and breach index Have I Been Pwned catalogued 732,200 unique email addresses alongside names, phone numbers, physical addresses, dates of birth, purchase history and partial payment card data.

Why it matters

Brinks Home is one more victim of the 2026 ShinyHunters playbook also seen at Questel, McKesson and EY: no exploit, just a persuasive phone call that defeats MFA, followed by bulk export from a SaaS CRM and a pay-or-leak demand. For a home security company, exposed customer addresses and support conversations carry an added physical-safety dimension beyond ordinary phishing risk.

Timeline

  1. According to ShinyHunters, attackers gain access through a Microsoft Entra voice-phishing call that tricks an employee into approving an authentication request.

  2. Brinks Home detects the intrusion and activates its incident response procedure.

  3. ShinyHunters adds Brinks Home to its data-leak site, claiming 4.9 million Salesforce records, with a 30 July deadline.

  4. Have I Been Pwned adds the leaked dataset, covering 732,200 unique email addresses.

Sources

  1. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/shinyhunters-claims-brinks-home-breach-threatens-to-leak-stolen-data/
  2. teiss.co.ukhttps://www.teiss.co.uk/news/shinyhunters-claims-brinks-home-breach-millions-of-salesforce-records-exposed-17926
  3. haveibeenpwned.comhttps://haveibeenpwned.com/Breach/BrinksHome
  4. foxnews.comhttps://www.foxnews.com/tech/brinks-home-data-breach-puts-1m-customers-alert

Related incidents