GoFirm
Back to Blog
Case Studies·4 min read

Brinks Home protects a million homes. It couldn't protect one login from a phone call.

By GoFirm

On 13 July 2026, according to the extortion group ShinyHunters, an employee at Brinks Home, the Texas-based residential security company that monitors alarms, cameras and smart home systems for more than a million customers across the United States, Canada and Puerto Rico, answered a phone call. The caller claimed to be from internal IT support and walked the employee through what looked like a routine Microsoft Entra authentication step. It was not routine. Completing it handed the caller a live session inside the employee's account, and with it, a path into Brinks Home's Salesforce environment.

Vishing of this kind follows the same script regardless of target: a confident voice, a plausible pretext, and a request dressed up as a security measure rather than a bypass of one. ShinyHunters told BleepingComputer it spent the following week moving through Brinks Home's systems undetected, pulling records out of the company's Salesforce Contacts object and its Cresta-hosted customer support chat logs. Brinks Home did not identify the intrusion until 20 July, seven days after the group says it first got in. By then, according to the attackers, more than 1.1 million rows of customer data, over 4,000 employee records including names, email addresses, job titles and phone numbers, and upward of 3.8 million customer support chat transcripts had reportedly left the network. ShinyHunters' overall claim reaches 4.9 million records.

Brinks Home has confirmed it identified an intrusion and that the attacker has threatened to publish the data it claims to hold. It has not yet confirmed the scope, and BleepingComputer has been unable to independently verify ShinyHunters' figures. What is not in dispute is the method: no malware, no exploited vulnerability, a single phone call that ended with a legitimate employee completing an authentication step for someone who was never entitled to ask for it.

Brinks Home generates roughly $830 million in annual revenue and employs around 1,500 people protecting homes with sensors, panels, cameras and smart locks. None of that hardware was touched. The company has confirmed its alarm monitoring and system functionality were unaffected, and is now warning its own customers to watch for phishing messages that impersonate Brinks Home in the wake of the breach, a secondary risk that the original vishing call has now set in motion. The incident adds Brinks Home to a growing list of 2026 breaches, including Charter Communications, Carnival and Medtronic, that share an identical opening move: a phone call convincing enough that the person on the other end completed the authentication step themselves.

The defences that failed here were not weak by conventional standards. Brinks Home had an incident response procedure it activated within days, engaged forensic investigators, and has been transparent with customers throughout. None of that mattered at the moment that counted, because the failure occurred earlier: at the point a single employee, acting in good faith, completed an authentication request from someone claiming to be IT support. Multi-factor authentication, single sign-on and Entra's own security controls all assume the person completing the step is who they say they are. They have no way to ask whether the request itself is genuine.

Microsoft Entra authentication and registration are execution events. Before an employee can complete one, whether prompted by a genuine IT ticket or a phone call from someone claiming to be IT, a confirmation request goes to a named authority on their own registered device, out of band from the call, the login screen, or the request itself. The vishing caller can be fluent, patient, and word-perfect. They cannot make that second device buzz in the named authority's pocket, and they cannot produce the biometric confirmation that unlocks it.

That is the control Brinks Home did not have on 13 July. The Entra session that opened Salesforce, the employee records, and 3.8 million support transcripts to an outside party was, at the moment it mattered, a single unconfirmed click. A vishing call, however convincing, cannot produce that confirmation. The execution boundary holds regardless of how credible the impersonation appears.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence.
Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.

References

1. Ilascu, I. 2026. ShinyHunters claims Brinks Home breach, threatens to leak stolen data. BleepingComputer, 30 July 2026.
2. SC Staff. 2026. Brinks Home confirms data breach after ShinyHunters claims attack. SC Media, 30 July 2026.

Share this article