Dormant Medium impact Data breach Checked 6d ago

ShinyHunters breach exposes Brinks Home customer data

Home security company Brinks Home confirmed hackers broke into part of its IT systems in July 2026. The ShinyHunters extortion group claimed it stole about 4.9 million Salesforce records and later leaked 41GB of files after the company did not pay. Brinks Home says its alarm monitoring and security systems kept working normally throughout.

Started
Jul 20, 2026
Latest activity
Aug 10, 2026
Attributed to
ShinyHuntersConfirmed
Where
United States
Sectors
Consumers, Retail
Scale
one company, about 1 million customers notified

Current status

As of August 10 media reported roughly 1 million customers were being notified, and no new confirmed activity has been reported since the August 3 leak.

Dormant: No new confirmed activity for a while, and nobody has called an official all clear.

Who is behind it

ShinyHunters publicly claimed the breach and posted the leaked files themselves; Brinks Home has not disputed the claim.

Impact

Attackers stole an estimated 4.9 million Salesforce records containing customer information and later published 41GB of the data online after an extortion deadline passed. The company says its physical alarm monitoring and system functionality were not disrupted.

What to do

Brinks Home customers should watch for a breach notification letter and be alert for phishing or scam calls referencing their account, since their contact details are now public.

Timeline

  1. Aug 10, 2026

    Reports said roughly 1 million customers were being notified after confirmation that about 4.9 million Salesforce records were stolen.

    Dormantfoxnews.com
  2. Aug 3, 2026

    ShinyHunters leaked 41GB of allegedly stolen Brinks Home data after the extortion deadline passed.

    Activesecurityweek.com
  3. Jul 30, 2026

    ShinyHunters publicly claimed the breach and threatened to leak stolen data if Brinks Home did not pay.

    Activebleepingcomputer.com
  4. Jul 20, 2026

    Brinks Home identified unauthorized access to part of its IT environment and activated incident response.

    Emergingbleepingcomputer.com

Sources