On 13 July 2026, according to the extortion gang ShinyHunters, an employee at Brinks Home received a phone call from someone claiming to be Microsoft IT support. Brinks Home is a residential security company serving more than a million customers across the United States, Canada and Puerto Rico, generating roughly $830 million in annual revenue with around 1,500 employees. The call was a Microsoft Entra voice phishing attempt, a technique in which the caller talks an employee through approving a legitimate looking authentication or device registration prompt rather than asking for a password outright. Brinks Home did not identify the intrusion until a week later, on 20 July, and only disclosed it publicly after ShinyHunters listed the company on its data leak site on 30 July.
The mechanics of the call are well documented across a wave of near identical intrusions this year. The caller does not ask the target to hand over a password or read out a one-time code. Instead they walk the employee through what looks like a routine identity check: approve this notification, register this device, confirm this sign-in. Each step is something the victim believes they are doing for their own account security. The prompt appears on the employee's own phone, inside Microsoft's own authenticator app, carrying Microsoft's own branding. Approving it hands the caller a live, authenticated session without a single password ever changing hands.
Once inside, ShinyHunters says it moved directly to Brinks Home's Salesforce environment. The group claims to have exfiltrated more than 1.1 million rows from the Contacts object, more than 4,000 rows of employee PII including names, email addresses, job titles and phone numbers, and over 3.8 million customer support chat logs from the company's Cresta instance. Brinks Home has not verified any of these figures and says it is still working to determine exactly what information was involved and whose.
Brinks Home is one entry in a longer list. The same Microsoft Entra vishing technique has been linked to intrusions across dozens of organisations this year, and ShinyHunters alone has claimed breaches at Ernst & Young, DentaQuest and a run of Salesforce-connected enterprises in the weeks either side of this one. The pattern repeats because the economics favour the attacker: a single fifteen-minute phone call, requiring no malware and no exploited vulnerability, can open a Salesforce instance holding years of customer records. Brinks Home says its alarm monitoring and system functionality were unaffected, but the exposure of customer and employee data, and the irony of a home security company unable to secure a phone call, is damage regardless of the final confirmed record count.
The defences that failed here were not weak by conventional standards. Multi-factor authentication was in place. The prompt the employee approved came from Microsoft's genuine authentication infrastructure, not a spoofed page. Nothing in the technical chain was forged. The failure sat entirely in the moment a person decided that a fluent, confident voice on the phone, speaking the language of internal IT support, was who it claimed to be. No password was stolen because none was needed. No malware was deployed because none was necessary. The account holder authenticated the attacker themselves, one tap at a time.
Approving a new device registration or authentication method on a corporate identity account is an execution event. It is the moment a session moves from unauthenticated to trusted, and everything downstream, Salesforce exports included, inherits that trust. Under GoFirm, that approval does not complete on the strength of a phone call alone. Before the registration or authentication request can be confirmed, a separate push notification goes out on the named authority's own registered device, over a channel the caller has no access to, requiring a live biometric confirmation before the action executes.
A ShinyHunters caller, however fluent and however convincing their impersonation of Microsoft IT support, cannot produce that confirmation on a device they do not hold. The execution boundary sits outside the phone call entirely, on hardware the attacker never touches, and it holds regardless of how credible the caller sounds.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.
References
1. Ilascu, I. 2026. ShinyHunters claims Brinks Home breach, threatens to leak stolen data. BleepingComputer, 30 July 2026.
2. SC Staff. 2026. Brinks Home confirms data breach after ShinyHunters claims attack. SC Media, 30 July 2026.
3. CVETodo. 2026. ShinyHunters Claims Brinks Home Breach via Microsoft Entra Vishing Attack, Threatens to Leak 4.9 Million Salesforce Records. CVETodo, 31 July 2026.
Back to Blog
Case Studies·4 min read
The Microsoft Entra prompt that handed ShinyHunters access to Brinks Home's Salesforce records
By GoFirm
