Brinks Home hit by breach after 41GB leak by ShinyHunters

Hackers accessed part of Brinks Home IT systems; ShinyHunters leaked over 41GB, including about 4.9 million Salesforce records.
Brinks Home, a Dallas-based home security provider, detected unauthorized access to a portion of its IT systems last week. The extortion group ShinyHunters posted more than 41 gigabytes of files it says were taken in the incident, and the group claims the data set includes roughly 4.9 million records from the company’s Salesforce environment.
The company told customers it is reviewing the files to determine what information was involved and who may be affected. Brinks Home said it will notify individuals directly if their personal information is found in the leaked material and advised customers to be alert to unsolicited emails, text messages or phone calls requesting personal information or account credentials.
Brinks Home reported that alarm monitoring and system functionality were not impacted because the attackers did not access its products or services. The company has not identified a responsible threat actor in its public notice; the disclosure coincided with the posting on a Tor-based leak site run by ShinyHunters.
According to the extortion group, the files were released after Brinks Home declined to pay a ransom demand. The company has not published a full inventory of the leaked data or confirmed the scope of the information posted online.
Investigators have not released details on how the attackers gained access, the timeline of the intrusion, or whether external forensic firms have been retained. The group that posted the files asserts some records contain personally identifiable information. Independent verification of the contents and extent of the published files has not been provided.
Customers impacted by the incident should watch for direct notifications from Brinks Home and consider routine security steps such as changing account passwords and checking accounts for unusual activity. The company reiterated that customers should remain cautious about unsolicited contacts requesting account details while the investigation continues.







