Brinks Home, a leading residential security provider in North America, has announced a security breach after the hacking group ShinyHunters claimed to have accessed its IT systems. The breach reportedly involves the theft of almost five million records associated with the company’s Salesforce database.
Details of the Breach
The confirmation from Brinks Home follows ShinyHunters’ public listing of ‘BH Security, LLC’ on their data leak website. The hackers demanded a ransom, threatening to disclose the stolen information if not paid by July 30, 2026. The company identified the unauthorized access on July 20 and responded swiftly to mitigate the breach.
The attackers reportedly had access for about a week before Brinks Home contained the breach. During this time, they are believed to have extracted over 1.1 million rows of customer data from the Salesforce ‘Contacts’ object, more than 4,000 rows of employee personal information, and approximately 3.8 million customer support chat logs from the Brinks Care Cresta platform.
Impact on Brinks Home and Its Customers
While the figures suggest a total of 4.9 million records were compromised, security experts indicate that these numbers include both records and chat logs rather than individual customer accounts. Brinks Home has yet to confirm the precise nature of the data affected or whose information was compromised.
Crucially, the company has assured that its core security services remain unaffected. The breach was limited to Salesforce and support systems, leaving the alarm monitoring and customer security hardware intact. This incident aligns with a pattern of attacks targeting Salesforce-related data, attributed to ShinyHunters throughout 2026.
Customer Advisory and Future Measures
Brinks Home has advised customers to be cautious of any unsolicited communications requesting personal details, stressing that the company will not solicit sensitive information in this manner. Should personal details be confirmed as compromised, the company commits to notifying affected individuals in compliance with legal requirements.
The company further advises against engaging with suspicious messages related to the breach and recommends verifying any communications through official channels. As cyber threats become increasingly sophisticated, customers are urged to remain vigilant and proactive in safeguarding their information.
For enhanced security, integrating advanced threat detection tools into security operations centers (SOCs) is recommended to accelerate incident response and investigations.
