The cybercrime group ShinyHunters has claimed responsibility for an attack against home security provider Brinks Home, alleging it obtained millions of customer records and internal company files. While the company has acknowledged a cybersecurity incident and confirmed it is being extorted, it says it has not yet verified the attackers’ claims regarding the data allegedly stolen.
Brinks Home disclosed that it identified suspicious activity within its environment on 20 July and immediately began responding to the incident. The company said it activated its incident response plan, engaged external digital forensics specialists and launched an investigation to determine how the intrusion occurred and what information may have been affected.
According to Brinks Home, its alarm monitoring operations and security services continued to function normally throughout the incident. The company said the attack did not interrupt customers’ monitored alarm systems or the availability of its security platform.
Shortly after the disclosure, ShinyHunters added Brinks Home to its data leak site, where the group threatened to publish information it claims to have extracted from the company’s systems. Brinks Home has confirmed that the attackers are attempting to extort the company and have threatened to release material they claim was stolen, but it has not confirmed the authenticity or scope of the alleged data.
According to reports, the threat actors claimed they initially gained access on 13 July by carrying out a voice phishing attack targeting Microsoft’s Entra identity platform. According to the group, an employee was persuaded to complete a fraudulent authentication process, allowing the attackers to compromise a corporate account. Brinks Home has not confirmed that this was the method used in the intrusion.
ShinyHunters alleges it copied more than 1.1 million customer contact records from Salesforce, over 4,000 employee records containing personally identifiable information, and approximately 3.8 million customer support chat logs from the company’s Brinks Care Cresta platform. Those figures originate solely from the attackers, and no independent verification has been provided.
Brinks Home says its investigation is ongoing and that it has not yet established exactly what information, if any, was accessed during the incident or whose data may have been involved. The company said it will directly notify affected individuals if the investigation determines their personal information was compromised and will provide guidance on any recommended protective measures.
While the forensic review continues, Brinks Home is warning customers to remain vigilant for phishing emails, text messages or phone calls that exploit publicity surrounding the breach. The company advises customers to treat unsolicited communications with caution, avoid opening unexpected links or attachments, and rely on official Brinks Home channels for updates until the investigation is complete.