Brinks Home Security investigates breach as ShinyHunters threatens to leak 4.9M Salesforce records
Hackers threaten to publish millions of records as Brinks races to determine what was stolen.

Image by Brinks Home
- ShinyHunters claims it stole 4.9 million Salesforce records from Brinks Home and threatens to publish them.
- Brinks Home, which serves more than 1 million customers, discovered unauthorized system access July 20 and is investigating the impact.
- The home security company says its alarm monitoring and customer services remain operational.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The notorious ShinyHunters gang has declared Brinks Home – the Texas-based home security giant – as its latest victim, claiming to have stolen 4.9 million Salesforce records from the company’s networks.
Brinks Home was listed in a July 27th update on the group's dark leak site, more than a week after revealing to its 1 million customers it was “investigating a corporate cybersecurity incident.”
ShinyHunters is now threatening to publish 4.9 million records allegedly taken from the company's Salesforce environment – alongside what it called “some compromised PII” or personally identifiable information.
"This is a final warning to reach out by 30 July 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline,”the ShinyHunters entry reads.
Brinks Home said it first became aware of the breach on July 20th after it had “identified unauthorized access to a portion of its IT systems.”
The security company did not specifically name the threat actor responsible for the intrusion, but did say in a July 22nd statement posted on its website:
“Brinks Home is aware that the party responsible for this incident has claimed it will release information it obtained, and that such material may be posted publicly.”
The company's post further claims that the attack did not involve any Brinks Home products or services.
“Alarm response and monitoring will continue without interruption,” it said.
Stolen data still under investigation
Headquartered in Dallas, Texas, Brinks Home is the third-largest home security company in North America, behind the US-based ADT and Vivint, The Edmonds Group reports.
The company offers 24/7 professionally monitored home and business security systems, including smart security cameras, alarm systems, home automation, video doorbells, and environmental monitoring.
In its statement, Brinks said it was still “working diligently to determine what information was involved and who may be affected.”
Brinks said it would notify affected individuals if it determines their personal information was compromised, as required by law and if appropriate.
"Our team is working around the clock alongside leading forensics experts to address this issue and help keep our customers safe and informed,"said William Niles, CEO at Brinks Home.
"Protecting our customers is at the core of everything we do, and we take the security of our systems just as seriously," the CEO said.
Brinks Home serves more than 1 million residential and commercial customers across the US and Canada, and Puerto Rico, and boasts one of the largest networks of independent authorized dealers and agents, according to its website.
The company’s 2025 revenue is estimated at about $800 million, according to ZoomInfo.
ShinyHunters widens its 2026 spree
Meanwhile, ShinyHunters has been ramping up attacks against high-profile organizations since the start of 2026.
Brinks Home happens to be the second major US home security company claimed by ShinyHunters this year.
In April, the group said it stole 2.5 million records from Alert360’s networks, later dumping the purported stolen data on the dark web after claiming the company refused to pay an undisclosed ransom demand.
Earlier this week, the notorious extortionists claimed to be behind a July breach on Ernst & Young (EY), one of the Big Four accounting firms. Shiny Hunters also threatened to leak a stolen cache of client documents by July 31st.
In June, the gang hit Sysco, the world’s largest food distributor, and American fashion giant Ralph Lauren, while other big-name victims in 2026 include Amtrak, Hims & Hers, Hallmark, the European Commission, and Ameriprise Financial.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
The well-known cybercrime and extortion gang has also been linked to several large-scale data theft campaigns, including last year’s Salesforce heist – carried out as part of the Scattered LAPSUS$ Hunters trio – and campaigns involving Okta and Oracle's PeopleSoft enterprise software.
The Salesforce attacks affected more than 700 other companies, including Cloudflare, Zscaler, Palo Alto Networks, Google, Allianz Life, TransUnion, Farmers Insurance, Air France, and KLM.
Researchers say the group often lures employees using sophisticated IT worker vishing campaigns that trick them into handing over their credentials, allowing the hackers to access victims’ internal systems.
Check if your data has been leaked