ShinyHunters claims Brinks Home breach
The notorious cybercrime group ShinyHunters has announced that it has hacked home security giant Brinks Home and is threatening to leak the personal data of millions of customers. The attack was allegedly carried out using a vishing method.
What Happened
Brinks Home, a leading name in the home security systems industry, has disclosed that some of its systems were breached by cyberattackers and that it faces threats of allegedly stolen data being published online. The company reported that it first identified the attack on July 20 and immediately activated its incident response procedures to contain the breach. This development took on a new dimension when the notorious extortion gang ShinyHunters, well-known in the cybersecurity world for its attacks on many large companies, claimed responsibility for the attack at the beginning of the week.
Brinks Home is a massive organization serving over one million customers across the United States, Canada, and Puerto Rico, with an annual revenue of approximately $830 million and employing nearly 1,500 people. The company offers home security systems like sensors, panels, and cameras, as well as smart home automation products such as locks, thermostats, and smart plugs. Having such a large customer base and a sensitive service area makes the potential impact of the attack even more alarming. The targeting of the digital infrastructure of a company to which customers entrust their home security is a situation that could deeply shake the perception of trust in the industry. The fact that the attackers targeted not only customer data but also the information of company employees shows how comprehensive the attack was.
The Stolen Data
ShinyHunters claims to have exfiltrated approximately 4.9 million records from Brinks Home's Salesforce database as a result of the attack. The details of these claims provide significant clues about the nature of the stolen data. According to information shared by the attackers with BleepingComputer, the exfiltrated data is grouped into three main categories:
- Customer Data: Over 1.1 million rows of customer data allegedly stolen from Salesforce's "Contacts" object. This type of data typically includes personally identifiable information (PII) such as first name, last name, address, email address, and phone number. The leakage of this information could leave customers vulnerable to targeted phishing attacks, identity theft, and other forms of fraud.
- Employee Data: Over 4,000 rows of personal information said to belong to Brinks Home employees. This data is reported to include full names, corporate email addresses, job titles, and phone numbers. This information poses a critical vulnerability that attackers could use to move further within the company or to target employees with social engineering attacks.
- Customer Support Logs: Over 3.8 million customer support chat logs allegedly stolen from the Brinks Care Cresta instance. These records may contain highly sensitive conversations about technical issues customers experienced, account details, and security concerns. Leaking these logs would not only violate customer privacy but could also expose potential weaknesses in customers' security systems.
BleepingComputer has specifically stated that it has not reviewed the data allegedly stolen by ShinyHunters and has been unable to verify the accuracy of these claims. However, Brinks Home has acknowledged the seriousness of the threat by confirming that the attacker "has threatened to release information it claims to have taken" and that "such material may be posted publicly."
How the Attack Happened
In a statement to BleepingComputer, ShinyHunters claimed that they breached Brinks Home on July 13 through a Microsoft Entra voice phishing (vishing) attack. This method is a version of traditional phishing attacks conducted over the phone and relies entirely on social engineering skills.
In this type of attack, the cybercriminal typically calls a company employee, posing as someone from the IT department, a service provider, or another trusted source. The attacker convinces the employee to complete a Microsoft Entra (formerly Azure AD) authentication or registration process under the pretext of resolving an urgent issue or a technical problem. This process often results in the employee sharing a multi-factor authentication (MFA) code, logging into a fake page by clicking a link, or granting access to the attacker's device. When successful, the attacker gains full access to the victim's account and can use it to move laterally within the network, access sensitive data, and exfiltrate it. Vishing attacks are particularly dangerous because they target the human factor rather than technical security measures and can bypass even the most secure networks.
Who is Affected
Those directly affected by the attack are both current and potentially former customers and employees of Brinks Home. If ShinyHunters' claims are true, the personal information of over 1.1 million customers and more than 4,000 employees is at risk. For customers, this risk could lead to serious consequences such as identity theft, financial fraud, and the misuse of information related to their home security. For employees, in addition to their personal security, there is a risk that their information could be used as a stepping stone against the company in future cyberattacks.
In its latest updates on the incident, Brinks Home stated that the investigation is ongoing and that it has "not yet confirmed exactly what information was involved or whose." This uncertainty requires all Brinks Home customers and employees to be cautious.
What You Can Do
If you are a Brinks Home customer or employee, there are several important points to be aware of during this time. The company is warning that attackers may exploit this incident by sending fraudulent messages impersonating Brinks Home or other parties involved in the response. Therefore, it is recommended to follow these steps:
- Be Wary of Suspicious Communication: Be on the lookout for emails, text messages, or phone calls that claim to be from Brinks Home but seem suspicious. Never respond to requests for your personal information, password, or account details.
- Do Not Click on Links: Do not click on any links or download attachments in suspicious messages. Such links may direct you to fake websites designed to steal more of your information.
- Delete the Messages: If you receive a suspicious communication, the safest course of action is to delete the message without responding.
- Use Official Channels: If you have a concern about your account or need to contact the company, do so through the phone number or customer service portal listed on the company's official website.
- Review Your Accounts: If you use the same password for Brinks Home on other online accounts, change those passwords immediately. Using different and strong passwords prevents a breach from affecting your other accounts.
What the Company Says
Brinks Home CEO William Niles stated that the company's team is working with "leading forensics experts to address this issue." The company emphasized that the attack did not in any way impact its alarm monitoring and system functionality, reassuring customers that their physical security systems continue to operate.
On its Frequently Asked Questions (FAQ) page for the incident, the company stated, "If we determine that your information was affected, we will notify you and explain what steps, if any, you should take." Brinks Home is urging its customers and employees to be proactively cautious and to follow announcements from the company's official channels until the investigation is complete. The company's ability to conduct a transparent communication process and inform affected individuals in a timely manner will play a critical role in managing this crisis.
Source
This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.