Brinks Home Suffers Data Breach Following Vishing Attack by ShinyHunters
Brinks Home, a leading residential security provider serving over 1 million customers across the U.S., Canada, and Puerto Rico, disclosed a data breach after hackers infiltrated its systems. The company detected the attack on July 20 and immediately launched an incident response, enlisting forensic experts to contain the breach. While alarm monitoring and system functionality remained unaffected, the threat actor identified as the ShinyHunters extortion gang claimed to have stolen sensitive data.
According to ShinyHunters, the breach occurred on July 13 via a Microsoft Entra voice phishing (vishing) attack, in which an employee was tricked into completing an authentication process, granting the hackers access. The group alleges it exfiltrated:
- 1.1 million+ rows of customer data from Salesforce’s "Contacts" object,
- 4,000+ rows of employee PII, including names, emails, job titles, and phone numbers,
- 3.8 million+ customer support chat logs from Brinks’ Care Cresta instance.
Brinks Home confirmed the attacker’s threat to leak the data but has not verified the full scope of the stolen information. The company stated it is still investigating and will notify affected individuals if their data is confirmed compromised. In the meantime, Brinks warned customers about potential fraudulent messages exploiting the incident.
With $830 million in annual revenue and 1,500 employees, Brinks Home offers security systems, smart home devices, and monitoring services. The breach highlights the growing risk of vishing attacks targeting enterprise authentication systems.
Brinks Home cybersecurity rating report: https://www.rankiteo.com/company/brinks-home
"id": "BRI1785435859",
"linkid": "brinks-home",
"type": "Breach",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '1 million+',
'industry': 'Residential Security',
'location': 'U.S., Canada, and Puerto Rico',
'name': 'Brinks Home',
'size': '1,500 employees, $830 million annual revenue',
'type': 'Company'}],
'attack_vector': 'Vishing (Voice Phishing)',
'customer_advisories': 'Warning about potential fraudulent messages '
'exploiting the incident',
'data_breach': {'data_exfiltration': 'Yes',
'number_of_records_exposed': '1.1 million+ (customer data), '
'4,000+ (employee PII), 3.8 '
'million+ (chat logs)',
'personally_identifiable_information': 'Names, emails, job '
'titles, phone numbers',
'sensitivity_of_data': 'High (PII, chat logs)',
'type_of_data_compromised': ['Customer data',
'Employee PII',
'Customer support chat logs']},
'date_detected': '2024-07-20',
'description': 'Brinks Home, a leading residential security provider, '
'disclosed a data breach after hackers infiltrated its systems '
'via a Microsoft Entra voice phishing (vishing) attack. The '
'threat actor, ShinyHunters, claimed to have stolen sensitive '
'customer and employee data, including 1.1 million+ rows of '
'customer data, 4,000+ rows of employee PII, and 3.8 million+ '
'customer support chat logs. Brinks Home confirmed the attack '
'but has not verified the full scope of the stolen '
'information.',
'impact': {'brand_reputation_impact': 'Potential brand reputation damage due '
'to data breach',
'data_compromised': 'Customer and employee data, customer support '
'chat logs',
'identity_theft_risk': 'High (PII exposed)',
'operational_impact': 'Alarm monitoring and system functionality '
'remained unaffected',
'systems_affected': 'Salesforce Contacts object, Care Cresta '
'instance'},
'initial_access_broker': {'entry_point': 'Microsoft Entra voice phishing '
'(vishing) attack'},
'investigation_status': 'Ongoing',
'motivation': 'Extortion',
'post_incident_analysis': {'root_causes': 'Vishing attack tricking employee '
'into completing authentication '
'process'},
'ransomware': {'data_exfiltration': 'Yes'},
'references': [{'source': 'Cyber Incident Description'}],
'response': {'communication_strategy': 'Customer advisories issued about '
'potential fraudulent messages',
'containment_measures': 'Immediate incident response launched',
'incident_response_plan_activated': 'Yes',
'third_party_assistance': 'Forensic experts enlisted'},
'threat_actor': 'ShinyHunters',
'title': 'Brinks Home Suffers Data Breach Following Vishing Attack by '
'ShinyHunters',
'type': 'Data Breach',
'vulnerability_exploited': 'Microsoft Entra authentication process'}