ShinyHunters has leaked more than 41GB of data allegedly stolen from Brinks Home’s Salesforce instance, claiming over 4.9 million records. Brinks Home says its alarm monitoring and products were unaffected, and it declined to pay the ransom. Bleeping Computer has more:
The company identified the attack on July 20 and immediately activated its incident response procedure to contain the breach.
William Niles, CEO at Brinks Home, said that the company’s team was working with “leading forensics experts to address this issue.”
The intrusion did not impact in any way the company’s alarm monitoring and system functionality.
At the beginning of the week, the ShinyHunters extortion gang claimed the attack on Brinks Home, alleging that they stole more than 4.9 million Salesforce records with personally identifiable information (PII).
Josh Picolet, VP of Detection & Analysis, Team Cymru had this to say:
“ShinyHunters’ targeting of Brinks Home’s Salesforce instance is consistent with a broader shift in extortion tradecraft. These groups are no longer relying primarily on network intrusion, they are going directly after the SaaS platforms where customer data actually lives, environments that sit outside the visibility most security teams have built their detection programs around. The leak site itself functions as operational infrastructure, a monetization channel that runs independent of whether a ransom gets paid, and treating it as an afterthought to the breach misses how central it is to the group’s business model. Defenders need to stop treating third-party and cloud platforms as someone else’s problem and start extending external visibility to cover them the same way they would their own network edge. The organizations that get ahead of this shift will be the ones tracking adversary infrastructure and monetization patterns, not just watching their own perimeter for signs of intrusion.”
Get ready. This won’t end well regardless of what Brinks does. ShinyHunters will make sure of that.
Related
This entry was posted on August 3, 2026 at 2:11 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
4.9 million records, one Salesforce instance, zero ransom paid
ShinyHunters has leaked more than 41GB of data allegedly stolen from Brinks Home’s Salesforce instance, claiming over 4.9 million records. Brinks Home says its alarm monitoring and products were unaffected, and it declined to pay the ransom. Bleeping Computer has more:
The company identified the attack on July 20 and immediately activated its incident response procedure to contain the breach.
William Niles, CEO at Brinks Home, said that the company’s team was working with “leading forensics experts to address this issue.”
The intrusion did not impact in any way the company’s alarm monitoring and system functionality.
At the beginning of the week, the ShinyHunters extortion gang claimed the attack on Brinks Home, alleging that they stole more than 4.9 million Salesforce records with personally identifiable information (PII).
Josh Picolet, VP of Detection & Analysis, Team Cymru had this to say:
“ShinyHunters’ targeting of Brinks Home’s Salesforce instance is consistent with a broader shift in extortion tradecraft. These groups are no longer relying primarily on network intrusion, they are going directly after the SaaS platforms where customer data actually lives, environments that sit outside the visibility most security teams have built their detection programs around. The leak site itself functions as operational infrastructure, a monetization channel that runs independent of whether a ransom gets paid, and treating it as an afterthought to the breach misses how central it is to the group’s business model. Defenders need to stop treating third-party and cloud platforms as someone else’s problem and start extending external visibility to cover them the same way they would their own network edge. The organizations that get ahead of this shift will be the ones tracking adversary infrastructure and monetization patterns, not just watching their own perimeter for signs of intrusion.”
Get ready. This won’t end well regardless of what Brinks does. ShinyHunters will make sure of that.
Share this:
Like this:
Related
This entry was posted on August 3, 2026 at 2:11 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.