ShinyHunters Claims Brinks Home Salesforce Data Theft 

ShinyHunters claims it breached Brinks Home through a Microsoft Entra vishing attack.

Written By
Ken Underhill
Ken Underhill
Jul 31, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Brinks Home is investigating a cybersecurity incident that attackers claim began with a Microsoft Entra voice phishing campaign targeting employee identities. 

The company confirmed an attacker has threatened to publicly release information allegedly stolen from its systems. 

“The party responsible for this situation has threatened to release information it claims to have taken. We are aware that such material may be posted publicly,” said Brinks in its notification. 

Key takeaways of the Brinks Home incident

  • Brinks Home is investigating a cybersecurity incident after ShinyHunters claimed it breached the company through a Microsoft Entra vishing attack.
  • The threat group alleges it stole Salesforce customer records, employee PII, and millions of customer support chat logs, although Brinks Home has not confirmed the scope of any data exposure.
  • According to ShinyHunters, the attack relied on identity-focused social engineering rather than exploiting a software vulnerability.
  • The incident follows other 2026 claims by ShinyHunters targeting cloud-based platforms, including Canvas and Udemy, highlighting the group’s continued focus on SaaS environments.
  • Phishing-resistant authentication, stronger identity governance, continuous cloud monitoring, and tested incident response plans remain important defenses against Microsoft Entra vishing and other identity-based attacks.

Inside the ShinyHunters attack on Brinks  

According to BleepingComputer, the ShinyHunters extortion group claims it breached Brinks Home on July 13 through a Microsoft Entra vishing attack that provided access to customer and employee data. 

Brinks Home serves more than 1 million customers across the United States, Canada, and Puerto Rico, providing residential security systems, cameras, sensors, and smart home automation products. 

Although the company has not confirmed what information, if any, was accessed, it acknowledged that the attacker has threatened to publicly release data it claims to have stolen.

According to ShinyHunters, the attack began with a Microsoft Entra vishing campaign. 

In these attacks, threat actors call employees and persuade them to approve authentication requests, register attacker-controlled devices, or complete identity verification steps that grant access to corporate accounts. 

Unlike attacks that exploit software vulnerabilities, vishing campaigns target the human element of identity security, allowing attackers to gain legitimate access to applications when successful.

Advertisement

ShinyHunters claims Salesforce and customer data theft 

The group alleges it exfiltrated more than 1.1 million customer records from a Salesforce Contacts object, more than 4,000 employee records containing personally identifiable information (PII), and more than 3.8 million customer support chat logs from a Brinks Care Cresta instance. 

BleepingComputer reported that it has not independently verified these claims, and Brinks Home has not confirmed the scope of any data exposure.

ShinyHunters continues targeting Cloud and SaaS platforms 

ShinyHunters has remained active throughout 2026, claiming responsibility for several high-profile data theft and extortion campaigns targeting cloud-based platforms. 

Earlier this year, the group claimed attacks against the Canvas learning management system and online education platform Udemy, using stolen data and public leak threats to pressure victims into negotiations. 

If confirmed, the Brinks Home incident would align with ShinyHunters’ pattern of targeting SaaS platforms, cloud applications, and identity-centric environments to steal data for extortion. 

How to defend against Microsoft Entra vishing attacks 

Vishing and other identity-based attacks continue to exploit human trust to gain access to cloud applications and other business-critical systems. 

  • Deploy phishing-resistant MFA, Conditional Access, and identity threat detection to reduce the risk of account compromise.
  • Strengthen help desk identity verification procedures and restrict unauthorized device registration and MFA enrollment.
  • Monitor Microsoft Entra, Salesforce, and other cloud platforms for unusual authentication activity, OAuth abuse, privileged account changes, and suspicious behavior.
  • Enforce least-privilege access, regularly review privileged accounts and authentication tokens, and use just-in-time administration where appropriate.
  • Secure service accounts, API credentials, and cloud identities by rotating secrets, removing unused credentials, and limiting excessive permissions.
  • Test incident response plans using simulations and scenarios around identity and SaaS compromise.
Advertisement

Collectively, these measures can help organizations reduce overall risk and limit the blast radius of identity-related incidents. 

Bottom line

Identity compromise continues to provide threat actors with a direct path into business-critical SaaS platforms that often contain large volumes of operational and customer data. 

For security leaders, the priority is no longer just preventing identity compromise but limiting what an attacker can reach after a trusted identity has been compromised. 

With identity serving as the new security perimeter, Zero Trust provides a framework for continuously validating access and limiting the blast radius of compromised accounts.

Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.