You buy a monitored alarm system to move risk off your shoulders and onto a company that does security for a living. The pitch is competence: they watch, they respond, they know what they are doing.

Then the company gets breached by someone who picked up a telephone.

What Happened

On July 13, 2026, attackers from the extortion group ShinyHunters placed a call to a Brinks Home employee. Not an exploit, not a zero-day — a Microsoft Entra voice phishing call, in which the caller impersonates internal IT and walks the target through an authentication flow that quietly hands the attacker a valid session.

Brinks Home discovered the unauthorized access on July 20, 2026. Four days later, on July 24, ShinyHunters listed the company on its dark web leak site with the usual ultimatum: pay, or the data goes public.

The company did not pay. The data went public.

What Was Taken

ShinyHunters claimed roughly 4.9 million customer records from the company’s Salesforce environment. Broken down:

  • 1.1+ million rows of customer data from the Salesforce “Contacts” object
  • 4,000+ rows of Brinks Home employee PII — full names, work emails, job titles, phone numbers
  • 3.8+ million customer support chat logs pulled from the Brinks Care Cresta instance

The data subsequently published and indexed by Have I Been Pwned included 732,000 unique email addresses alongside names, phone numbers, physical addresses, purchase records, and partial payment card data — last four digits, card type, and expiry.

Brinks Home confirmed the intrusion, engaged outside forensics, and warned customers not to respond to messages impersonating the company. CEO William Niles said the team was “working with leading forensics experts to address this issue.” The company serves over a million customers across North America on roughly $830 million in annual revenue.

Why the Support Chat Logs Are the Worst Part

Most breach coverage fixates on record counts. The number that should worry a Brinks customer is 3.8 million support chat transcripts.

Think about what you say to your alarm company’s support agent. My back door sensor keeps false-alarming. I need the code changed, my ex-partner still has it. We’re away until the 20th, can you confirm the system’s armed? The camera over the garage isn’t recording.

A customer contact record tells an attacker you have an alarm. A support chat log tells them which part of it doesn’t work, and when you’re not home. Combined with the physical address in the same dump, that is not identity-theft material — that is target-selection material, sorted and searchable.

This is the same reason the ADT breach in April was worse than its headline number, and the reason home security vendors sit in a different risk category than an ordinary retailer. A leaked shoe-store customer list is a fraud problem. A leaked alarm-company customer list is a physical safety problem, and it does not expire when you change your password.

Twice in Four Months, the Same Phone Call

Look at the pattern:

ADTBrinks Home
DiscoveredApril 20, 2026July 20, 2026
AttackerShinyHuntersShinyHunters
Initial accessVishing an employee’s Okta accountVishing an employee’s Microsoft Entra login
Records~5.5 million~4.9 million claimed
OutcomeRefused payment, data leakedRefused payment, data leaked

Two of the largest residential security providers in the United States, four months apart, same crew, same technique, roughly the same result. Neither breach involved a flaw in an alarm panel, a camera, or a lock. Both involved a human being on a phone and an identity system that trusted what happened next.

That is a well-understood industry-wide campaign at this point — ShinyHunters has run this playbook against Salesforce tenants across dozens of companies — and the defense against it is equally well understood. Which is what makes the repetition so frustrating.

The Defense Both Companies Were Missing

A vishing call works because the attacker can get the victim to relay something — a code, an approval, a push confirmation. Phishing-resistant authentication removes the thing there is to relay.

A FIDO2 hardware security key performs a cryptographic handshake bound to the genuine site’s origin. On an attacker-controlled page, or when a voice on the phone asks you to approve something you didn’t initiate, there is nothing to read out, nothing to forward, and nothing to approve. The handshake simply does not complete. Both of these breaches would have hit a wall at step one.

That is a control your alarm company owes you. It is also one you can apply to your own accounts today — the Google, Amazon, Apple, and vendor logins that actually control the locks, cameras, and voice assistants in your house. We covered exactly how to roll hardware keys out across your smart home accounts in an evening, and the open-source Nitrokey remains our pick for people who want auditable firmware in the thing guarding everything else.

Nitrokey FIDO2 security key — open source, phishing-resistant

What Brinks Customers Should Do Now

Assume your address, phone number, and alarm-vendor relationship are public. They are. Plan for what an informed stranger can do with that, not for whether it can be undone.

Expect targeted impersonation, and set a rule now. The single most likely follow-on attack is a call or email from “Brinks” referencing real details of your account — because the caller has your real details. Establish a household rule: you hang up and call the number on your bill. Never the number in the message. Brinks itself has warned about exactly this.

Rotate every code and credential you can. Your alarm panel user codes, the account password, and any duress or verbal passcode on file. If a verbal passcode appeared in a support chat transcript, it is burned.

Turn on phishing-resistant MFA on the alarm account if the vendor supports it, and on your email account regardless — email is the recovery path to everything else.

Watch for card fraud even though only partial numbers leaked. Last four, card type, and expiry are enough to make a social-engineering call to another company sound convincing.

Freeze your credit if you have not already. It is free, it takes fifteen minutes, and this is the third large-scale exposure of home-security customer data in under a year.

Bottom Line

Nobody defeated a Brinks alarm. They defeated a Brinks employee, over the phone, in the time it takes to make a support call — and the CRM behind the alarm turned out to hold more useful intelligence about your house than the alarm itself protects.

When you choose a monitored security provider, you are not only buying sensors and a response contract. You are handing a company your address, your schedule, your household’s routine, and a running transcript of every weakness you have ever asked them to fix. Ask what protects that. “Passwords and a help desk” is now a demonstrably wrong answer, twice over, in four months.

Sources

Affiliate disclosure: This article contains affiliate links. If you purchase through our links we may earn a commission at no extra cost to you.