Brinks Home Confirms Data Breach After ShinyHunters’ Claim

Brinks Home, a leading provider of residential security services in North America, has confirmed a data breach following claims by the cyber extortion group ShinyHunters. The group alleges it has stolen nearly five million records from the company’s Salesforce environment.

The breach was detected on July 20, 2026, prompting Brinks Home to activate its incident response procedures immediately. The company has since been working with external cybersecurity experts to investigate and contain the incident. Despite the breach, Brinks Home assures that its core products and services, including alarm monitoring and system functionality, remain unaffected and continue to operate without interruption.

ShinyHunters claims to have exfiltrated over 1.1 million rows of customer data from the Salesforce “Contacts” object, more than 4,000 rows of employee personally identifiable information (PII) such as names, emails, job titles, and phone numbers, and approximately 3.8 million customer support chat logs from the Brinks Care Cresta platform. These figures total the 4.9 million records advertised on the group’s leak site. However, security researchers note that this number reflects a sum of records and chat transcripts rather than a distinct customer headcount.

Brinks Home has stated that it has not yet confirmed the exact information compromised or the individuals affected. The company is aware that the party responsible for this incident has claimed it will release the obtained information publicly. Brinks Home is diligently working to determine what information was involved and who may be affected. If personal information is confirmed to be affected, the company will notify impacted individuals as required by applicable law and outline any recommended next steps.

Customers are advised to remain vigilant against unsolicited emails, texts, or phone calls requesting personal information or credentials. Brinks Home emphasizes that it will never request sensitive data through unsolicited communication. Customers should verify any communication directly through official Brinks Home channels rather than numbers or links provided in unsolicited messages.

This incident is part of a broader pattern of Salesforce-focused phishing campaigns attributed to ShinyHunters throughout 2026, which have previously targeted organizations like Cushman & Wakefield, Kodak, and Sysco using similar social engineering tactics against single sign-on providers such as Microsoft Entra and Okta.

Stolen customer support transcripts are particularly concerning as they contain service addresses, equipment details, and account history, making follow-up phishing attempts appear highly credible. Brinks Home urges customers to be cautious and report any suspicious communications.

As cyber threats continue to evolve, this breach underscores the importance of robust cybersecurity measures and proactive incident response strategies. Organizations must remain vigilant and continuously assess their security protocols to protect sensitive customer and employee information.