Jul 31, 2026
Policy

Brinks Home data breach claim tied to ShinyHunters Salesforce records

Brinks Home says part of its IT environment was accessed, while ShinyHunters claims it took 4.9 million Salesforce records.

Dominic Okoye

By Dominic Okoye · Staff Writer

· 3 min read

Brinks Home data breach claim tied to ShinyHunters Salesforce records
Photo: The Register

Brinks Home disclosed unauthorized access to part of its IT systems, and a Brinks Home data breach claim by ShinyHunters now centers on more than 4.9 million alleged Salesforce records. The home and business security provider has not identified the intruder or the affected platform, but said the party behind the incident has threatened to publish information it claims to have taken.

Brinks Home said it is still determining what data was involved and who may have been affected. The company said it will notify people if it finds that personal information was compromised, as required and as appropriate. It has not said how many customers or employees may be affected, whether any ransom demand was received, or whether the incident involved Salesforce.

The company’s incident FAQ says Brinks Home products and services are not believed to be affected at this stage. That means alarms and other physical security systems should be operating normally, based on the company’s current assessment.

Was Brinks Home breached by ShinyHunters?

Brinks Home has not publicly named ShinyHunters. Ransomware.live, which monitors leak sites, reported that ShinyHunters claimed responsibility and said it obtained more than 4.9 million Salesforce records from Brinks Home containing some personally identifiable information.

According to Ransomware.live, the group threatened to release the data and cause unspecified “annoying digital problems” unless Brinks Home contacted it by Thursday, July 30, to discuss a ransom. The amount of any demand was not disclosed. The Register reported that Brinks Home did not respond to messages, and that its contacts for ShinyHunters no longer appeared to work.

The alleged Salesforce angle matters because ShinyHunters has been linked to a run of Salesforce-related intrusion claims. Earlier this year, the group claimed it had stolen data from Salesforce instances belonging to about 100 high-profile companies.

Salesforce has previously warned that a known threat actor, which it did not name, was scanning public-facing Salesforce instances and abusing misconfigured guest accounts. A Salesforce guest account is intended to let unauthenticated users access limited functions, such as a public portal. If permissions are set too broadly, it can become a route into data the company did not mean to expose.

What Brinks Home has and has not said

  • Brinks Home confirmed unauthorized access to a portion of its IT systems.
  • The company said the responsible party threatened to leak information it claims to possess.
  • Brinks Home has not named the attacker.
  • Brinks Home has not identified Salesforce as the affected system.
  • The company says its security products and services are not known to be affected.

The brand context is messy. Brinks Home is no longer part of The Brinks Company, the larger security and logistics business. The Brinks Company told The Register that it sold the home security unit in 2010.

Brinks Home’s parent company, Monitronics, has also been through bankruptcy twice since 2019. That does not prove anything about the incident, but it adds pressure to a company whose customers are buying trust in physical security and whose attacker is now making claims about weaknesses in its business systems.

This story draws on original reporting from The Register.

More from Policy

All Policy →