The most famous brand in physical security got pwned by ShinyHunters
Jump to main content
Search
REG AD
security
The most famous brand in physical security got pwned by ShinyHunters
Hopefully the company secures houses better than it locks down SaaS systems
Brandon Vigliarolo
Brandon<br>Vigliarolo
GOVERNMENT AND IT NEWS REPORTER
Published<br>fri 31 Jul 2026 // 17:27 UTC
A leading name in home and business physical security, Brinks Home, recently said it identified unauthorized access to a portion of its IT systems, an intrusion ShinyHunters claims it carried out to steal millions of records from the security provider's Salesforce instance.<br>Brinks Home hasn’t named the intruder or identified the affected system, but said the responsible party has threatened to leak information it claims to have taken.<br>“Brinks Home is working diligently to determine what information was involved and who may be affected,” the company statement said. “If the Company determines that personal information has been affected, it will notify those individuals as required and as appropriate.”
REG AD
An FAQ page for the incident said that Brinks Home products and services weren’t affected, as far as the company knows at this point, so alarms and other security tools should be working without issue.
REG AD
While Brinks may not have been very forthcoming with information, and lacks any sort of official way for media to communicate with it outside of sending a LinkedIn message it didn’t answer, the party that’s claimed responsibility has gone public with some details, and it’s none other than ShinyHunters with another claimed Salesforce breach.<br>According to leak site monitoring outfit Ransomware.live, ShinyHunters claimed to have obtained more than 4.9 million Salesforce records from Brinks Home “containing some PII.” The group threatened this week to leak the data along with causing “several annoying digital problems” if Brinks Home didn’t reach out by Thursday, July 30, to negotiate a ransom payment.<br>It’s not clear if Brinks Home has contacted ShinyHunters; Brinks Home didn’t respond to messages, and contacts The Register has for ShinyHunters appear to have changed, causing message and email rejections.<br>ShinyHunters has been a prolific Salesforce intruder of late, with the group claiming earlier this year to have stolen data from around 100 high-profile companies’ Salesforce instances. Salesforce has previously warned that an unnamed known threat actor group was actively scanning for public-facing Salesforce instances and abusing misconfigured guest accounts to break in.
MORE CONTEXT
Moody Bible Institute breach leaves 2.3M accounts needing salvation, says cyber expert
Council of Europe hacked in ShinyHunters' PeopleSoft heist
ShinyHunters adds Charter to trophy shelf after 4.9M customer records leak
Have I Been Pwned claims Pitney Bowes hit by 8.2M email address leak
Brinks Home is no longer part of the larger Brinks brand, with The Brinks Company telling us it sold the home security arm in 2010. Brinks Home’s parent company, Monitronics, has filed for bankruptcy twice since 2019; for customers’ sake, we hope its physical security services are better than its financial management and infosec. ®
data breach<br>saas<br>security<br>salesforce
REG AD
DEVOPS
Dev who gave HashiCorp its name returns with a faster terminal multiplexer
Persistent sessions could be just the beginning
security
The most famous brand in physical security got pwned by ShinyHunters
Hopefully the company secures houses better than it locks down SaaS systems
From individual achievement to partner impact
PARTNER CONTENT: Databricks survey data suggests certified professionals lift partner delivery capacity, customer credibility, and AI readiness well beyond the individuals who earn the credential
Cyber-crime
US bank places trust in ransomware crew that promised to delete its data
History suggests this was not wise
PAAS AND IAAS
Amazon's Q2 was great, but the earnings release is packed with baloney
"Tell me lies, tell me sweet little lies"
SECURITY
Anthropic and OpenAI are competing to see whose agents can go rogue harder
Whoever wins, we lose
MOST POPULAR
security
DEF CON bans Meta-style 'pervert glasses'
security
Word worm crawls into Copilot, spreads chaos
DATABASES
After rewriting SQLite in Rust, Turso turns its sights on Postgres
software
Techie lured out of retirement to support software only he remembered
AI and ML
Closed models refuse to help researcher swat Linux bug
AI
DEVOPS
Dev who gave HashiCorp its name returns with a faster terminal multiplexer
Persistent sessions could be just the beginning
SECURITY
Anthropic and OpenAI are competing to see whose agents can go rogue harder
Whoever wins, we lose
SYSTEMS
UK wants datacenters to pay a fee for grid connection requests
Refundable charge intended to discourage time wasters from filing applications that will never be realized
STORAGE
GPUs could explode to...