{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-brinks-home-breached-after-microsoft-entra-vishing-call-to-an-employee"},"incident":{"slug":"2026-brinks-home-breached-after-microsoft-entra-vishing-call-to-an-employee","title":"Brinks Home breached after Microsoft Entra vishing call to an employee","date":"2026-07-13","date_precision":"day","year":2026,"victim_org":"Brinks Home","sector":"Consumer","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"Residential security company Brinks Home disclosed that attackers gained access on 13 July 2026 through a Microsoft Entra voice phishing attack in which an employee was persuaded to complete an authentication process. The intrusion was discovered on 20 July. ShinyHunters claimed more than 4.9 million records from the company's Salesforce instance, including over 1.1 million rows of customer contact data, more than 4,000 employee records and roughly 3.8 million customer support chat logs. Alarm monitoring was unaffected.","how_it_worked":"The caller presented as internal IT and asked the employee to complete an authentication step, which in practice approved the attacker's own Entra sign-in rather than the employee's. That authenticated identity federated through to Salesforce, where a home security provider stores customer contact records, employee directory data and years of support chat transcripts. Seven days passed between the call on 13 July and discovery on 20 July. Brinks Home warned customers to expect fraudulent messages impersonating the company, since the stolen chat logs make convincing follow-on pretexts.","lessons":"Phishing-resistant MFA removes the approval the caller needs, and alerting on unusual Salesforce report or export volume would have cut a seven-day dwell time to hours.","confidence":"Confirmed","sources":[{"title":"ShinyHunters claims Brinks Home breach, threatens to leak stolen data","url":"https://www.bleepingcomputer.com/news/security/shinyhunters-claims-brinks-home-breach-threatens-to-leak-stolen-data/","publisher":"BleepingComputer"},{"title":"Salesforce Hacks 2026: Everything We Know So Far","url":"https://www.salesforceben.com/salesforce-hacks-2026-everything-we-know-so-far/","publisher":"Salesforce Ben"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-brinks-home-breached-after-microsoft-entra-vishing-call-to-an-employee"}}