Protect.Computer
NEWS

ShinyHunters Hacks Brinks Home via Vishing, Claims 1.1M Records

· 1 min read · Identity theft Data hijack
ShinyHunters Hacks Brinks Home via Vishing, Claims 1.1M Records

Home security company Brinks Home confirmed this week that hackers broke into some of its systems and are threatening to release stolen data unless paid. The breach was discovered on July 20, and CEO William Niles said the company immediately activated its incident response plan. Alarm monitoring and security system functionality were unaffected throughout the incident.

The ShinyHunters extortion gang claimed responsibility, telling BleepingComputer that it gained access on July 13 through a Microsoft Entra voice-phishing (vishing) attack — calling a Brinks Home employee and tricking them into completing a Microsoft Entra authentication step that handed the attackers control of that account. From there, ShinyHunters says it exfiltrated more than 1.1 million customer records from the Salesforce “Contacts” object (including personal details), over 4,000 employee records (names, email addresses, job titles, and phone numbers), and roughly 3.8 million customer support chat logs from Brinks’ Care Cresta instance. BleepingComputer was unable to independently verify the stolen data, but Brinks Home confirmed the attacker has threatened to publish what it claims to have taken. Brinks Home serves more than one million residential security customers across the United States, Canada, and Puerto Rico. ShinyHunters has previously conducted similar vishing-based Salesforce breaches against Charter Communications and 7-Eleven.

Sources

Related reading