Hackers Called One Brinks Home Employee and Gained Access to One Million Customer Files

fx-visual via shutterstock

ShinyHunters breached AT&T twice and Ticketmaster with 560 million records – and nobody stopped them.

Now the same criminal gang has their sights on the company you trusted to protect your home.

They didn't crack a single password to get inside Brinks Home – and that's what should terrify you.

How One Phone Call Opened the Door to Your Security Company

The break-in started July 13 with a phone call.

A ShinyHunters operative called a Brinks Home employee and pretended to be from the company's own IT department.

The criminal walked that employee through a Microsoft Entra authentication process.

The employee approved it.

That one approval handed the hackers the keys to Brinks Home's entire Salesforce environment – the digital backbone holding information on over a million customers.

Brinks Home didn't even know they were inside until July 20, which means the attackers had a full week to roam through company systems before anyone noticed.

ShinyHunters claims they walked out with 4.9 million Salesforce records.

The group says that haul includes more than 1.1 million rows of customer contact data, over 4,000 employee records with names, email addresses, job titles, and phone numbers, and – this is the part that should stop you cold – 3.8 million customer support chat logs.

Your Support Chats Are Now a Weapon Against You

Think about what you've told Brinks Home over the phone or in a chat.

Maybe you called to ask about a sensor that kept triggering false alarms.

Maybe you mentioned the door code your technician used during installation.

Maybe you rattled off your emergency contacts when you updated your account.

Every one of those conversations is now potentially in criminal hands.

Brinks Home CEO William Niles confirmed the company brought in outside forensic experts and activated its incident response plan the moment they discovered the intrusion.

Alarm monitoring continues normally – your physical security hardware was not touched.

But the data breach investigation remains, in their words, "early and ongoing," and the company has not confirmed publicly whether the stolen data was released after ShinyHunters' July 30 ransom deadline passed.

The FBI Knows Who These People Are and Still Can't Stop Them

ShinyHunters isn't some amateur operation running out of a basement.

This is a criminal enterprise active since 2019 that has breached over 400 companies, compromised nearly 2 billion records, and built one of the most recognizable names in cybercrime – while federal law enforcement watched.

They hit AT&T in 2021, exposed 70 million customer records, and watched AT&T deny it for three years – then came back in 2024 with 110 million records and a reported $370,000 ransom payment.

They hit Ticketmaster the same year and listed 560 million customers' personal data for $500,000.

In 2026 alone they've run this exact same phone-call-into-your-Salesforce playbook against more than 40 organizations.

The FBI did arrest one member – a French programmer – in 2022, sentenced him to three years, and ordered him to pay more than $5 million in restitution.

The gang didn't slow down for a single day.

Vishing attacks like the one that opened Brinks Home's front door surged 442% in 2024 alone, according to CrowdStrike's Global Threat Report.

The federal government has had seven years to make this group too costly to operate.

They haven't.

What You Need to Do Right Now

Brinks Home will notify you directly if their investigation confirms your personal information was involved.

But criminals don't wait for corporate timelines.

Do not trust any call, text, or email claiming to be from Brinks Home unless you initiated the contact yourself.

Hang up and call back through the official number in the Brinks Home app.

Never read a one-time authentication code to anyone on the phone – that is the last step a criminal needs to take over your account.

Change your Brinks Home password now, especially if you reused it anywhere else.

If you ever mentioned your alarm code, verbal security password, or account PIN in a support chat, contact Brinks Home through official channels and ask whether that credential should be changed.

The company's reporting line is 469-391-4024 and their cybersecurity update page is at brinkshome.com/cybersecurity-update.

They know your name, your equipment, and the last problem you called about.

Any call that leads with that information is not Brinks Home – it's someone using your own history against you.


Sources:

  • Ionut Ilascu, "ShinyHunters claims Brinks Home breach, threatens to leak stolen data," BleepingComputer, July 30, 2026.
  • "Brinks Home Confirms Data Breach Following ShinyHunters Claim," Cybersecurity News, August 2026.
  • "Brinks Home confirms data breach after ShinyHunters claims attack," SC Media, August 2026.
  • "ShinyHunters: The Group Behind 300+ Breaches," Security Boulevard, May 2026.
  • "ShinyHunters 2026: Every Breach, Every Victim, Every Method," State of Surveillance, May 2026.
  • "Vishing attacks increased by 442% in the second half of 2024," Security Magazine, March 2025.
  • "Aura data breach," Wikipedia, 2026.