Brinks Home confirmed a 2026 breach of its Salesforce environment after the ShinyHunters group stole customer records in a voice-phishing attack. Leaked data includes roughly 732,000 email addresses plus names, phone numbers, home addresses, purchase records, and partial card details. Alarm monitoring was not affected. Your real risk now is targeted scam calls.
What Happened in the Brinks Home Data Breach?
Brinks Home — the residential security and alarm-monitoring company — was hit as part of the wider 2026 Salesforce extortion wave run by the ShinyHunters group. The pattern is the same one that hit dozens of large enterprises: attackers call an employee, impersonate internal IT, and talk them through authorizing access. In this case the entry point was reported as a Microsoft Entra vishing (voice phishing) attack on July 13, 2026.
Brinks Home says it identified unauthorized access to a portion of its IT systems on July 20, 2026 and activated incident response the same day. In early August, after extortion demands were not met, ShinyHunters published data they claim came from the company.
Your Alarm System Was Not Hacked
This breach hit Brinks Home's Salesforce CRM and customer-support infrastructure — not the alarm hardware or the monitoring network. Your sensors, panel, cameras, and monitoring service continued operating normally. The exposure is your customer record, not your home security.
What Data Was Exposed?
The dataset published by the attackers and indexed by breach-notification services contains roughly 732,000 unique email addresses belonging to Brinks Home leads, customers, and staff, alongside:
- Full names
- Phone numbers
- Physical home addresses
- Purchase and product records — what security equipment and plan you bought
- Partial payment card data — last four digits, card type, and expiry date
- Employee PII for several thousand Brinks staff, including names, work emails, job titles, and phone numbers
ShinyHunters separately claimed a far larger haul: more than 1.1 million rows from the Salesforce "Contacts" object and roughly 3.8 million customer support chat logs, for a total they described as about 4.9 million records. Brinks Home has not confirmed those figures.
What was not in the leak, based on available reporting: full card numbers, bank account numbers, Social Security numbers, and account passwords.
Why This Combination Is Dangerous
No Social Security numbers means this is not a classic new-account identity theft breach. It is something arguably harder to defend against: a social engineering kit.
An attacker holding your name, home address, phone number, the security system you bought, and the last four digits of your card can call you and sound exactly like Brinks Home. They can reference your actual equipment. They can read back your card's last four to "verify" you. That is enough to talk many people into a payment "update," a remote-access install, or a code sent to their phone.
The support chat logs are worse in a subtle way: they may contain whatever you typed into a support session, including details about your home, your schedule, or your account.
Step 1: Assume the Call Is Fake Until You Call Back
For the next several months, treat any inbound call, text, or email claiming to be Brinks Home as hostile — no matter how much they know about you. Knowing your address and equipment is now worthless as proof of identity, because that is exactly what leaked. Hang up and dial the number on your billing statement or the official Brinks Home website. Never use a callback number the caller gives you.
Step 2: Watch the Card That Ends in Those Four Digits
Full card numbers were not exposed, so you do not automatically need a replacement card. But the last four plus expiry is a convincing prop in a scam call. Turn on transaction alerts for that card, review the last two statements, and if you get a call referencing it, treat that as confirmation someone is working the leaked list.
Is your data already out there?
Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.
Run a free scan★★★★★ 4.8/5 · Trusted by thousands of families
Step 3: Change Your Brinks Home Password and Turn On App-Based 2FA
Passwords were not reported as exposed, but change it anyway if you reused it anywhere else — credential-stuffing follows every leak of this size. Enable two-factor authentication on your Brinks Home account and, wherever possible, use an authenticator app rather than SMS. Phone numbers leaked here, which makes SMS codes and SIM-swap attempts a realistic follow-up.
Step 4: Freeze Your Credit as a Free Backstop
A credit freeze at Equifax, Experian, and TransUnion is free, takes about 15 minutes total, and blocks new-account fraud even if your data later surfaces in a bigger dump. There is no downside — you can thaw it temporarily whenever you actually apply for credit.
Step 5: Remove Your Address and Phone Number From Data Brokers
This is the step that changes your exposure rather than just monitoring it. The Brinks leak is dangerous because it is combinable. On its own it gives an attacker your address and phone. Cross-referenced with people-search sites, it also gives them your age, relatives' names, previous addresses, property records, and additional phone numbers — everything needed to make a scam call sound airtight.
PrivacyOn removes your personal information from 100+ data broker and people-search sites, monitors for re-listings, and scans the dark web for your details starting at $8.33/month, with family plans covering up to 5 people. Cutting off the broker half of the profile makes the leaked half far less useful. Run a free PrivacyOn scan to see which sites are publishing your address and phone right now.
Step 6: Watch for the Breach Notification — and Verify It
Brinks Home has said it will notify individuals whose personal information was confirmed compromised. Expect that letter by mail. Be aware that fake "breach notification" emails are a standard follow-up to any publicized incident: they arrive fast, look official, and link to a credential-harvesting page. Do not click links in any breach email — go to the company's site directly.
Quick Checklist
Verify every inbound Brinks call by calling back on a known number. Turn on card transaction alerts. Change reused passwords and switch 2FA to an app. Freeze all three credit bureaus. Remove your address and phone from data brokers. Ignore links in breach emails.
Frequently Asked Questions
Was I affected by the Brinks Home data breach?
If you were a Brinks Home customer, a sales lead, or an employee before July 2026, assume you may be in the dataset. The published leak contains roughly 732,000 unique email addresses covering leads as well as active customers, so you can be included even if you never completed a purchase. Check your email address on a reputable breach-notification service and watch for a mailed notice from Brinks Home.
Was my Social Security number exposed in the Brinks Home breach?
Based on available reporting, no. The leaked fields are contact details, purchase records, and partial card data — not Social Security numbers, full card numbers, or bank account numbers. That lowers the new-account fraud risk but raises the scam-call risk, because attackers now hold details that make impersonating Brinks Home easy.
Do I need to cancel my credit card?
Not automatically. Only the last four digits, card type, and expiry were exposed, which is not enough to make a charge. Turn on transaction alerts and review recent statements instead. Replace the card if you see any unrecognized activity or if a caller uses those four digits to pressure you.
Is my Brinks alarm system or camera feed compromised?
No. The intrusion was in Brinks Home's Salesforce CRM and support systems, not the alarm monitoring network or your on-site equipment. Monitoring service was not interrupted. Still, change your account password and enable app-based two-factor authentication as basic hygiene.
How do I stop the scam calls that follow a breach like this?
Register with the National Do Not Call Registry, enable your carrier's spam-call filtering, and never confirm personal details to an inbound caller. The bigger lever is reducing how much of your profile is publicly purchasable: PrivacyOn removes your name, address, and phone number from 100+ data broker sites, which is where callers get the extra context that makes their script convincing.
What is ShinyHunters and why do they keep appearing in 2026 breaches?
ShinyHunters is an extortion group that spent 2025 and 2026 running voice-phishing campaigns against employees at large companies to gain access to their Salesforce environments, then demanding payment to not publish the stolen data. Brinks Home is one of many victims in that wave, alongside other well-known consumer brands.