Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Jul 31, 2026 · 7 min read

ShinyHunters Hit Brinks Home via a Phone Call

No malware, no zero day. An attacker called a Brinks Home employee on 13 July 2026, walked them through a Microsoft Entra prompt, and walked out with a Salesforce tenant.

The company that sells you a keypad by the front door lost its customer list to someone who dialed a phone number. Brinks Home has confirmed an intrusion that began on 13 July 2026 and was contained on 20 July. ShinyHunters says it left with 1.1 million customer records and 3.8 million support chat logs. Nobody had to write an exploit.

Key Takeaways

  • ShinyHunters breached Brinks Home on 13 July 2026 via a Microsoft Entra voice phishing call that convinced an employee to complete an authentication prompt, BleepingComputer reported on 30 July.
  • Brinks Home contained the incident on 20 July 2026, seven days after initial access.
  • The gang claims 1.1 million rows from the Salesforce Contacts object, over 4,000 rows of employee PII, and 3.8 million support chat logs from the Brinks Care Cresta instance.
  • Its leak site listing advertises 4.9 million Salesforce records and set a 30 July deadline; Brinks Home says it has not confirmed what information was involved or whose.
  • BleepingComputer has not reviewed the allegedly stolen data and could not verify the claims.
A residential front door at dusk with a glowing home security keypad panel mounted beside it and a smartphone face down on an entry table inside

What Happened to Brinks Home?

An attacker phoned a Brinks Home employee on 13 July 2026 and talked them through completing a Microsoft Entra authentication, which handed over the employee's account and the SaaS applications behind it.

Brinks Home, filed on the leak site as BH Security LLC, serves more than a million customers across the United States, Canada and Puerto Rico. It caught the intrusion on 20 July, seven days in — not a bad dwell time by industry standards, and more than enough to run a Salesforce export.

Ten days later the listing went public with a 30 July deadline, posted alongside Ernst & Young and RingCentral. CEO William Niles said the company was working with leading forensics experts, and Brinks Home has not confirmed what was taken or whose it was. One more caveat: BleepingComputer has not seen the data and could not verify the gang's numbers.

How Did a Phone Call Defeat MFA?

Because the MFA in the way was an approval, not a proof, and an approval can be requested by anyone who has convinced you they are IT.

The mechanic: the attacker triggers a sign in against the target's account, then calls while the prompt is live and coaches the employee through it — approve the push, read back the six digit code, enroll a new authenticator. The employee is not being careless. They are being helpful to a voice that already knows their name.

Microsoft draws the line explicitly. Its Entra ID authentication strengths documentation lists only three phishing resistant methods: FIDO2 security keys, Windows Hello for Business or platform credentials, and multifactor certificate based authentication. Text messages, voice calls and push notifications sit in the weaker tier labelled "something the user has." Phishing resistant methods bind the credential to the sign in surface, so a stranger on the phone cannot relay it. A push prompt has no idea who asked for it.

Do the Numbers Add Up?

Not to 4.9 million people, no. The leak site headline says 4.9 million Salesforce records containing PII, but the itemized claim tells a different story.

Break it out: 1.1 million rows from the Contacts object, 4,000 plus rows of employee PII with full names, email addresses, job titles and phone numbers, and 3.8 million support chat logs from the Brinks Care Cresta instance. Add the two large figures and you land on 4.9 million exactly. The headline number appears to be contacts plus chat transcripts summed together — a row count, not a headcount. Against a customer base of "over 1 million," the 1.1 million contacts figure is the one that describes people, and it implies roughly three and a half recorded support conversations each.

Extortion listings inflate by design. The only confirmed facts come from Brinks Home's own confirmation: an intrusion occurred, scope unknown. Treat everything else as a claim.

Why Are Support Chat Logs the Dangerous Part?

A chat log with a home security company is a written record of where you live, what protects it, and what has already gone wrong with it. An email address buys an attacker a guess; a transcript buys a script. In this vertical the transcripts plausibly carry:

  • Service address and account number, because you confirm both before support will do anything.
  • Equipment model and configuration — panel type, camera count, sensors that were failing.
  • Service history and timing, including the week you asked to suspend monitoring while you were away.
  • Your own phrasing, which makes a forged reply read like a continuation instead of a cold open.

Somebody who can write "following up on your 2 June ticket about the rear door sensor" does not need to sound convincing. They already are. Report scams built on that material to the FBI's Internet Crime Complaint Center.

Is This a Pattern or a One Off?

It is a pattern, and a well documented one. Six days before the Brinks Home listing went up, Health-ISAC issued a 24 July advisory that described this exact attack chain: vishing an employee or helpdesk into a password reset, MFA change or device enrollment, then using the compromised SSO account — Microsoft Entra, Okta or Google — as a springboard into Salesforce, Microsoft 365, SharePoint, Slack and Dropbox. Its fix was FIDO2 or WebAuthn keys for high risk groups plus a "no same call" rule for helpdesk resets.

The victim list runs long. In commercial real estate it was the same vishing playbook used against Cushman & Wakefield, which confirmed a breach after a claim of 500,000 Salesforce records. Kodak confirmed exfiltration on 17 June; DentaQuest's 234GB affected 2.6 million people. The group later dumped 2.7 million Sysco email addresses when a deadline passed. Different industries, one phone script. The irony of a home security company losing its customer list is a distraction: the constant here is the call, not the vertical.

What This Means for Your Inbox

If this data lands publicly, the consequence is not fraud on your alarm account. It is mail that knows things. "Watch for suspicious emails" is nearly useless advice when the attacker holds your service history — the tells people rely on, a wrong name or a generic greeting, get erased by a leaked transcript. What arrives will cite a real ticket and a real date, then ask for something small: confirm your account, download an invoice, approve a technician visit.

The employee list is its own problem: 4,000 rows of names and titles is a targeting file for the next round of vishing, aimed at the helpdesk that can reset accounts. At the crude end of the market, leaked addresses now feed a sextortion scam that works because one true detail makes a fabricated threat feel researched. Expect a few precise lures and a lot of noise. The pattern kept working through the summer: Levi Strauss disclosed in August that three employees were talked out of their access with no exploit involved.

What Should You Do Now?

Assume the data is out and change how you handle contact.

  • Treat unsolicited calls from "your provider" as hostile. Hang up and dial the number printed on your bill. A caller who knows your account number has proven nothing, because that number is in the stolen set.
  • Never approve an authentication prompt you did not start. Not for a caller, not for a colleague, not for a manager. A prompt appearing while somebody tells you to accept it is the attack, in progress.
  • Move to hardware keys or passkeys wherever they are offered. CISA's guidance on implementing phishing resistant MFA ranks the options; FIDO2 and WebAuthn survive the relay that push and SMS do not.
  • Check your exposure. Run your addresses through Have I Been Pwned and turn on notifications; dumped ShinyHunters sets have landed there within weeks before.
  • Verify out of band, and freeze credit if billing data is in scope. A security freeze at the three US bureaus is free and reversible.

The industry spent a decade telling people to turn MFA on. The 2026 lesson is that which MFA you turned on is now the entire answer.

Sources: BleepingComputer, ShinyHunters claims Brinks Home breach, BleepingComputer, Health-ISAC warns of rising ShinyHunters data theft attacks, Microsoft Learn, Conditional Access authentication strengths, BreachNews, ShinyHunters adds EY, RingCentral and Brinks Home to leak site, SC Media, Brinks Home confirms data breach, and CISA, Implementing Phishing Resistant MFA.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.