What happened
Residential security company Brinks Home disclosed that attackers gained access on 13 July 2026 through a Microsoft Entra voice phishing attack in which an employee was persuaded to complete an authentication process. The intrusion was discovered on 20 July. ShinyHunters claimed more than 4.9 million records from the company's Salesforce instance, including over 1.1 million rows of customer contact data, more than 4,000 employee records and roughly 3.8 million customer support chat logs. Alarm monitoring was unaffected.
How the deception worked
The caller presented as internal IT and asked the employee to complete an authentication step, which in practice approved the attacker's own Entra sign-in rather than the employee's. That authenticated identity federated through to Salesforce, where a home security provider stores customer contact records, employee directory data and years of support chat transcripts. Seven days passed between the call on 13 July and discovery on 20 July. Brinks Home warned customers to expect fraudulent messages impersonating the company, since the stolen chat logs make convincing follow-on pretexts.
The control that would have caught it· our reading, not a claim from the sources
Phishing-resistant MFA removes the approval the caller needs, and alerting on unusual Salesforce report or export volume would have cut a seven-day dwell time to hours.
Sources (2)
- ShinyHunters claims Brinks Home breach, threatens to leak stolen dataBleepingComputer·bleepingcomputer.comOpen ↗
- Salesforce Hacks 2026: Everything We Know So FarSalesforce Ben·salesforceben.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.