Brinks Home Investigates Claimed Salesforce Data Breach by ShinyHunters
Brinks Home, a major provider of residential and commercial security services, says it has detected unauthorized access to part of its information technology environment. The disclosure follows a clai...
Brinks Home, a major provider of residential and commercial security services, says it has detected unauthorized access to part of its information technology environment. The disclosure follows a claim by the ShinyHunters cybercrime group that it obtained millions of records from the company’s Salesforce environment.
In a public statement, Brinks Home said it is investigating what information was involved and which individuals may be affected. The company did not identify the alleged attacker or specify the systems involved. It said it will notify people as required if the investigation determines that personal information was compromised.
An incident FAQ published by the company said there is currently no indication that Brinks Home products or services were affected. Customers’ alarm systems and other security offerings are therefore not known to have been disrupted.
Ransomware.live, which monitors criminal leak sites, reported that ShinyHunters claimed access to more than 4.9 million Brinks Home Salesforce records containing some personally identifiable information. The group reportedly threatened to publish the data and create additional digital disruption unless the company opened ransom negotiations by July 30. It remains unclear whether Brinks Home engaged with the group.
Part of a broader Salesforce targeting campaign
The claim comes amid a series of alleged Salesforce compromises attributed to ShinyHunters. The group has said it accessed data belonging to roughly 100 prominent organizations this year. Salesforce has previously warned that a known threat actor was scanning exposed instances and taking advantage of misconfigured guest accounts.
Neither the scale of the alleged exposure nor the authenticity of the data has been independently confirmed. Brinks Home’s investigation will need to establish whether the claimed records came from its systems, what categories of information they contain, and whether customers or employees face any risk.
Brinks Home is separate from The Brink’s Company, which sold its home-security business in 2010. The company operates under Monitronics, which has experienced financial difficulties in recent years. Those corporate matters are unrelated to the reported cyber incident, but the breach claim highlights the importance of securing cloud applications and reviewing access controls.
