# ShinyHunters Vished Their Way Into a Home Security Giant — and Walked Out With 4.9 Million Records
The company that's supposed to keep your home safe just got social-engineered out of your data.
Brinks Home confirmed this week that attackers breached its systems around July 13 and have threatened to leak what they claim is a haul of 4.9 million Salesforce records. The intrusion became public after ShinyHunters — the extortion group responsible for a string of high-profile data theft campaigns over the past two years — listed Brinks on their leak site and described, in some detail, exactly how they got in.
The answer is disarmingly low-tech: a phone call.
## The Call That Opened the Door
ShinyHunters told BleepingComputer they used a Microsoft Entra voice phishing attack — a technique where the threat actor calls an employee and talks them through completing an Entra authentication or MFA registration flow, handing over account access in real time. The target doesn't need to click a malicious link or download anything. They just need to be convinced by a voice on the phone that completing the prompt is routine.
This attack class has been climbing the charts. It's the same social engineering playbook that Scattered Spider used to devastating effect against MGM and Caesars in 2023, and it's continued to spread because it works against organizations that have hardened their email-borne attack surface but haven't applied the same rigor to voice-based threats. Identity providers like Entra have become the crown jewel for initial access precisely because a single compromised account can unlock enormous swaths of downstream SaaS infrastructure.
In Brinks Home's case, that SaaS infrastructure included Salesforce — which ShinyHunters claimed to have pivoted to after gaining the foothold.
## What Was Actually in the Vaults
The group claims a three-part haul:
That last one deserves more attention than it's getting. Chat logs from a home security customer service system aren't just names and email addresses. They're transcripts of conversations about alarm codes, false alarm events, technician visits, home layouts, and account security concerns. For a company with over a million customers across the U.S., Canada, and Puerto Rico, that's a dataset with real physical-world implications — the kind that could help a determined bad actor case a target or craft highly convincing follow-on scams.
Brinks Home has confirmed the attacker is threatening to release "information it claims to have taken" but has not yet verified exactly what data was involved or whose. The company says it will notify affected individuals if it determines their data was exposed — a timeline that, given the scale of the claimed exfiltration, may take weeks.
## Alarm Monitoring Is Fine. Your Data Is Another Story.
Brinks was careful to emphasize that its alarm monitoring and system functionality were unaffected by the breach. That's worth noting because it's the kind of distinction that reassures institutional buyers and signals operational resilience. But for the residential customers who trusted Brinks with their home security data, the alarm staying on isn't the point.
The breach was detected on July 20, a week after the attacker claims to have been inside. During that window, ShinyHunters says it exfiltrated everything. The company activated its incident response procedure and brought in forensics experts — the language CEO William Niles used is careful and appropriately non-committal — but the window for data exfiltration had already closed.
Brinks is now warning customers that threat actors may exploit the incident to send fraudulent messages impersonating the company. That's standard post-breach advice, but it lands with unusual weight here: customers who received suspicious calls or emails from someone pretending to be Brinks security support should be genuinely alarmed, because the attacker already has enough customer context to make those impersonations highly credible.
---
## HackWire Analysis
ShinyHunters has been on a methodical campaign in 2026, and the Brinks breach reveals a targeting logic that goes beyond opportunism.
The group has increasingly gone after organizations that aggregate large volumes of consumer PII through customer relationship and service platforms — Salesforce, Zendesk, Cresta. These aren't the crown jewels in the traditional sense (no source code, no financials), but they're goldmines for follow-on fraud and extortion at scale. A dataset of 3.8 million customer service chat logs is worth more to an extortion operation than a database dump, because it provides narrative context: what customers were worried about, what problems they had, what they told a support rep in an unguarded moment.
The Microsoft Entra vishing vector is the detail defenders should be stress-testing right now. Organizations that have deployed phishing-resistant MFA — FIDO2 hardware keys, passkeys — are largely immune to this class of attack. Organizations still relying on authenticator app push notifications or SMS are not. The "MFA fatigue" attack that made headlines in 2022 has evolved; attackers now don't even wait for the victim to approve a rogue push. They call and narrate them through it.
What's also missing from most coverage: the Cresta integration. Cresta is an AI-powered customer support platform — pulling its data isn't just getting chat transcripts, it's potentially getting whatever structured data Cresta uses to assist agents, including customer history, account flags, and internally resolved issues. The full scope of that exposure likely won't be clear until Brinks completes its forensic review.
For defenders: audit your Entra conditional access policies today. Confirm that your security team has completed Entra-specific vishing scenarios in tabletop exercises. And if your customer data lives in Salesforce, assume that Salesforce access is a target — monitor for unusual exports and bulk API queries against Contact and Account objects.
— HackWire Editorial
---
## Related Coverage