Brinks Home, one of North America’s largest residential security providers, has confirmed that hackers breached its IT systems after the notorious ShinyHunters extortion group claimed responsibility for stealing nearly five million records tied to the company’s Salesforce environment.
The confirmation comes after the threat actors listed “BH Security, LLC (brinkshome.com)” on their leak site, threatening to publish the stolen data unless the company paid a ransom by July 30, 2026.
Brinks Home reported that it detected unauthorized access to its systems and promptly activated incident response procedures to contain the breach. The company discovered the intrusion on July 20, which meant that the attackers had approximately a week of dwell time before the breach was contained.
Brinks Home Confirms Data Breach
ShinyHunters claims to have exfiltrated more than 1.1 million rows of customer data from the Salesforce “Contacts” object, over 4,000 rows of employee PII including names, emails, job titles, and phone numbers, and roughly 3.8 million customer support chat logs from the Brinks Care Cresta platform.
ShinyHunters Claim
Combined, these figures add up to the 4.9 million records advertised on the group’s leak site, though security researchers note the headline number reflects a sum of records and chat transcripts rather than a distinct customer headcount.
Brinks Home has stated it has not yet confirmed exactly what information was compromised or whose data was involved.
Importantly, Brink’s Home has emphasized that the breach does not affect its core products or services. Alarm monitoring and system functionality for customers continue to operate without interruption, since the compromised systems were tied to Salesforce and support infrastructure rather than the security hardware or monitoring network itself.
This incident fits a broader pattern of Salesforce-focused vishing campaigns attributed to ShinyHunters throughout 2026, which have previously hit organizations like Cushman & Wakefield, Kodak, and Sysco using the same social engineering playbook against SSO providers such as Microsoft Entra and Okta.
Security experts warn that stolen customer support transcripts are especially dangerous because they contain service addresses, equipment details, and account history that make follow-up phishing attempts appear highly credible.
Brinks Home has urged customers to remain vigilant against unsolicited emails, texts, or phone calls requesting personal information or credentials, stressing that the company will never request sensitive data through unsolicited communication.
If personal information is confirmed to be affected, Brinks Home says it will notify impacted individuals as required by applicable law and outline any recommended next steps.
Customers are advised not to click links or respond to suspicious messages referencing the breach, and to verify any communication directly through official Brinks Home channels rather than numbers or links provided in unsolicited messages.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
The post Brinks Home Confirms Data Breach Following ShinyHunters Claim appeared first on Cyber Security News.


