GoFirm
Back to Blog
Case Studies·4 min read

A vishing call convinced Brinks Home's Microsoft Entra system to accept an attacker as an employee

By GoFirm

On 13 July 2026, according to the extortion group ShinyHunters, a phone call to a single Brinks Home employee was enough to open the company's Microsoft Entra environment to an outsider. Brinks Home, the Dallas-based home security provider that protects more than a million customers across the United States, Canada and Puerto Rico, did not detect the intrusion for a week. The company activated its incident response procedures on 20 July, engaged an external forensics firm, and has been investigating ever since. It has not confirmed how the attacker got in.

ShinyHunters told BleepingComputer that the entry point was a Microsoft Entra voice phishing call, a caller posing as Brinks Home's own technology department who persuaded an employee to complete what looked like a routine authentication or device registration step. That single approval, made in good faith over the phone, gave the caller a foothold inside the account and the business tools connected to it. No firewall was breached and no password was guessed. An employee did what the caller asked, because the caller sounded exactly like the department that was supposed to be helping them.

From there, ShinyHunters claims it moved through Brinks Home's Salesforce environment and adjacent systems, pulling more than 1.1 million rows from the company's Contacts object, over 4,000 employee records containing names, email addresses, job titles and phone numbers, and more than 3.8 million customer support chat logs from the Brinks Care Cresta platform. Those chat logs matter as much as the contact records: a conversation about an installation date or a billing dispute gives a scammer exactly the kind of detail that makes a follow-up phishing call sound legitimate. The group added Brinks Home to its leak site and set a deadline of 30 July for the company to respond. That deadline has passed. No data has been confirmed published, and Brinks Home has not verified any of ShinyHunters' figures.

Brinks Home says its alarm monitoring and physical security systems continued operating normally throughout, which is the reassurance a security company most needs to give its customers. It is also almost beside the point. The exposure here is not to a control panel or a sensor. It is to more than a million people's contact details and, potentially, the private conversations they had with a company they trusted to protect their homes. ShinyHunters has run this same playbook, a phone call, an Entra approval, a Salesforce export, against dozens of organisations this year, and Brinks Home is only the latest to confirm an incident without confirming what was taken.

The defences that failed here were not weak by conventional standards. Brinks Home had an incident response plan, activated it within a week of an anomaly surfacing, and brought in outside forensic specialists immediately. None of that mattered at the moment that counted: the moment an employee, on the phone with someone who sounded like internal IT, approved an authentication step that handed a stranger the keys. Multi-factor authentication is built to stop a stolen password. It is not built to stop an employee who is persuaded, calmly and convincingly, to complete the process themselves.

A Microsoft Entra device or authentication registration is an execution event, not a routine IT ticket. Before that registration can complete, a confirmation request goes to Brinks Home's named security authority, on their own registered device, over a channel entirely separate from the phone call or portal the attacker is using. If that authority does not confirm, the registration does not go through, no matter how convincing the caller sounds or how urgent the request appears.

That separation is the entire point. ShinyHunters' caller could sound exactly like Brinks Home's IT department, could reference real internal details, could create genuine urgency, and none of it would matter. A vishing call, however convincing, cannot produce a biometric confirmation from the real authority on the device they actually hold. The execution boundary holds regardless of how credible the impersonation appears.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence and governance network for Security, Resilience & Defence teams.


1. Ilascu, I. 2026. ShinyHunters claims Brinks Home breach, threatens to leak stolen data. BleepingComputer, 30 July 2026.
2. Knutsson, K. 2026. Brinks Home data breach puts 1M customers on alert. CyberGuy, 7 August 2026.

Share this article