← BACK TO FEED
data breachShinyHuntersextortionBrinks HomeSalesforce

ShinyHunters Dumps 41GB of Brinks Home Data After Ransom Goes Unpaid

Brinks Home, a Dallas-based home security firm, has suffered a data breach carried out by the ShinyHunters extortion group, who claim to have stolen over 4.9 million records from the company's Salesforce instance. After Brinks Home refused to pay a ransom, the hackers leaked more than 41GB of files online, which allegedly include personally identifiable information (PII). The company has confirmed the breach but stated that its alarm monitoring and core security systems were not affected, and is working to identify impacted individuals.

The ShinyHunters extortion group has followed through on its threats against Brinks Home, leaking more than 41 gigabytes of files allegedly lifted from the Dallas-based home security firm.

Brinks Home, which sells residential alarm systems and runs a 24/7 monitoring centre, confirmed last week that attackers had accessed part of its IT infrastructure and were threatening to publish stolen data. The company's statement was vague on specifics, promising to notify affected individuals if personal information was confirmed compromised and telling customers to watch out for phishing attempts off the back of the incident.

One thing they were keen to stress: the alarm monitoring systems kept running. Whatever the attackers got into, it apparently wasn't the operational side of the business.

ShinyHunters, meanwhile, was considerably more forthcoming. The group claims to have pulled nearly 4.9 million records from Brinks Home's Salesforce environment, some of which allegedly contain personally identifiable information. When no ransom materialised, they published the lot on their Tor-hosted leak site. ShinyHunters is not a group known for bluffing.

Brinks Home has not publicly named ShinyHunters as responsible, though the timing of the company's disclosure and the group's post to their leak site lines up fairly neatly.

SecurityWeek notes it has not independently verified the contents of the leaked files, so the full scope of what was actually taken remains unconfirmed. That said, 41GB is not nothing, and nearly five million Salesforce records is a reasonably specific claim to be making up.

READ NEXT
Anubis Ransomware Gang Claims Fairlife Hit, Gives Coca-Cola One Week to PayShinyHunters Breach Exposes Data of 3.8 Million Medtronic PatientsMedtronic Tells Patients Their Health Data May Have Walked Out the Door in April Breach