You hire a home security company to help protect your house. So, hearing that hackers broke into the company’s own computer systems may feel especially unsettling. Brinks Home has confirmed that an unauthorized party accessed part of its IT environment. The Dallas-based company says its alarm monitoring and security systems continue to work normally.
However, the intruder has threatened to release information it claims to have stolen. The Brinks Home data breach could affect a wide audience. Brinks Home says it serves residential customers in all 50 states. It also says it protects more than 1 million people across North America. For now, customers face a frustrating gap. Brinks Home has not confirmed exactly what information was accessed or who may be affected.
New! Free live CyberGuy class: Protect Your Money From Today’s Biggest Threats
Join us Saturday, Aug. 29, at 10 a.m. ET for a free CyberGuy LIVE class covering five simple steps to help defend yourself against AI scams, fraud, identity theft and financial hacks. Kurt “CyberGuy” Knutsson will explain how to set up bank alerts, strengthen your account logins, protect your phone number, freeze your credit and help secure your retirement savings against unauthorized transfers. No technical experience is needed. You’ll also receive our financial protection checklist, and every registrant will get a link to the class recording afterward.
Reserve your free spot today at CyberGuyLive.com.
COULD THE 7-ELEVEN BREACH AFFECT YOU?
Brinks Home discovered unauthorized access to part of its systems on July 20, 2026. The company activated its incident response procedures and moved to contain the intrusion. It also brought in outside cybersecurity experts to investigate. William Niles, CEO of Brinks Home, said the company was working with leading forensic experts to address the incident.
CyberGuy reached out to Brinks Home for additional comment. The company confirmed that its response began as soon as it detected the intrusion. “Brinks Home recently identified a security incident in which an unauthorized party gained access to certain company systems. Upon discovering the incident, we immediately activated our incident response plan, contained the activity, and engaged an industry-leading cybersecurity forensics firm to investigate,” Brinks Home told CyberGuy.
The company’s most reassuring update involves its security services. Brinks Home says the incident did not involve its products or monitoring services based on what it knows so far. Your security panel and sensors should continue working. Emergency monitoring should also remain available without interruption. However, the investigation has not determined the full scope of the incident.
Brinks Home stressed that its investigation remains in the early stages. “Our investigation is early and ongoing. Our systems are secure, and we are continuing to assess the full scope and potential impact of the incident while closely monitoring our environment,” the company said. “If we determine that your information was affected, we will notify you and explain what steps, if any, you should take,” the company says in its cybersecurity FAQ.
The ShinyHunters extortion group has claimed responsibility for the attack. The gang alleges that it stole more than 4.9 million records from Brinks Home’s Salesforce environment. That number refers to database records. It does not mean 4.9 million separate people were affected. One customer may appear in several records.
According to ShinyHunters, the stolen information includes more than 1.1 million rows from a Salesforce customer contacts database. The hackers also claim they obtained more than 4,000 employee records. Those records allegedly contain names, email addresses, job titles and phone numbers. In addition, the group claims it stole around 3.8 million customer support chat logs from the Brinks Care Cresta platform. Those claims have not been independently verified.
BleepingComputer says it has not reviewed the allegedly stolen data. The publication could not confirm the hackers’ figures or descriptions. Brinks Home has not confirmed that those specific records were taken. It also has not confirmed that personal information was compromised. That distinction is important. Criminal groups often mix real information with inflated claims to increase pressure on a company. The FBI has warned that ShinyHunters uses real or exaggerated claims while demanding payment. The gang may also use threatening messages or harassing phone calls.
ShinyHunters told BleepingComputer that it entered Brinks Home’s systems on July 13. The group claims it used a Microsoft Entra voice phishing attack. This type of attack is also called vishing. During a vishing attack, a criminal calls an employee while pretending to work for the company’s technology department.
The caller may say the employee needs to complete an account update. The criminal then guides the employee through an authentication or device registration process. If the employee approves the request, the hacker may gain access to the account and its connected business tools. Brinks Home has not confirmed this version of events. Its FAQ says the company is still investigating the incident.
Still, the allegation highlights a growing problem. A hacker may not need to crack a password when an employee can be persuaded to approve access. Voice phishing has helped criminals break into other corporate cloud accounts. That makes unexpected login requests especially dangerous.
A customer support chat may sound less sensitive than a password. However, those conversations can contain useful personal details. You may have discussed an installation date or a billing problem. Perhaps you mentioned the equipment installed in your house. A chat could also reveal your contact details, previous service issues or the names of authorized account users. Criminals can use those details to make a scam feel familiar.
For example, a caller might know that you recently contacted Brinks Home. The person could mention your equipment before claiming that an urgent security update is required. That context may make the call sound legitimate. It can also lower your guard before the criminal asks for a password or authentication code. The FBI warns that criminals can use stolen real-world context to create highly convincing phishing campaigns. You can learn more about how exposed contact information helps criminals launch attacks in our guide to ways scammers can use your phone number.
Brinks Home is warning customers to stay alert for suspicious communications related to the breach. A scammer might pretend to represent Brinks Home. The person could also claim to be a cybersecurity investigator or another party involved in the response. The message may say that your data will be released unless you act immediately. It could direct you to a fake login page or ask you to confirm account credentials.
Brinks Home says it will never ask you to provide sensitive information through an unsolicited communication. That warning deserves your attention even though the company has not confirmed whose data was involved. Hackers do not need a complete customer database to start sending scams. They may use public information or previously stolen data to target people while news of the breach spreads.
ShinyHunters threatened to release the alleged data if Brinks Home did not respond by July 30, 2026. That deadline has passed. However, as of today, Brinks Home had not publicly confirmed that customer information had been released. Its official update continued to say that the company was investigating what information may have been involved.
The absence of a confirmed leak does not prove that the hackers lack the information. At the same time, the group’s claims should not be treated as established facts without evidence. Customers should focus on what they can control now. That includes securing their accounts and becoming more suspicious of unexpected requests.
These steps can help protect your accounts, devices and identity while Brinks Home continues its investigation.
Be cautious if someone contacts you about the breach and asks you to confirm personal information. A scammer may claim that your alarm will stop working. The person might also say your account needs an urgent security update. Do not use a link or phone number included in the message. Instead, open the official Brinks Home app yourself. You can also type the company’s website address directly into your browser.
Do not trust a caller simply because the person knows your name or account details. Hang up and contact Brinks Home through the app or its official website. Avoid calling a number supplied by the person who contacted you. The FBI recommends verifying unusual requests through a separate communication method before responding.
A legitimate representative should not ask you to read aloud a one-time security code. That code may be the final step a criminal needs to enter your account. End the call if someone asks for one. Also, never approve an unexpected login notification. Select deny or reject when you did not initiate the request.
Change your password if you reused it on another website. You should also change it if you notice unusual account activity or receive an unfamiliar login alert. Create a long password that you have never used for another account. A password manager can create and store a different password for every login. That way, one exposed password cannot unlock several accounts. Pay close attention to your email password. Your email account may control password resets for Brinks Home and many other services.
FAKE SHINYHUNTERS SEXTORTION EMAIL USES CARNIVAL BREACH DATA
A data removal service can request that data brokers and people-search websites remove your personal information. This may include your home address, phone number and relatives’ names. Removing those details can make it harder for scammers to combine breached records with information found elsewhere online. However, a data removal service cannot erase information already taken from Brinks Home. It also cannot guarantee that stolen data will disappear from criminal forums. Its value comes from reducing the extra information scammers can use to build a convincing profile about you. Data broker profiles can reappear, so ongoing monitoring and repeated removal requests may be necessary. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting CyberGuy.com.
Multifactor authentication adds another check after you enter your password. An authenticator app or physical security key can offer stronger protection than a code sent through a text message. Turn on the strongest option available for your Brinks Home account. You should also protect your primary email account. Our guide to the top multifactor authentication apps explains how these tools work.
Open the Brinks Home app or customer portal and review your account information. Check your email address and phone number. Look for unfamiliar authorized users or account changes. Confirm that your emergency contacts and recovery information remain correct. If you ever shared an alarm code or verbal security password in a support chat, contact Brinks Home through an official channel. Ask whether that credential should be changed. Do not change settings through a link sent in an unexpected message.
An exposed phone number can help a criminal attempt a SIM swap or number transfer scam. Contact your wireless carrier and add an account PIN. Ask whether it offers a port-out lock or number transfer lock. These protections can make it harder for someone to transfer your phone number and intercept security codes. You should also use an authenticator app instead of text-message codes when an account offers that choice.
Install strong antivirus software on your computer and mobile devices. This protection can help detect malicious links, fake websites and suspicious downloads before they cause harm. It may also warn you when a phishing page tries to steal your password. Antivirus software cannot reverse the Brinks Home breach. However, it can provide another layer of defense against scams that follow it. Keep the antivirus software updated and allow it to run automatic scans. You should also install operating system, browser and app updates as they become available. Strong antivirus tools can block malware, dangerous websites and unsafe downloads in real time. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com
Brinks Home has not confirmed that Social Security numbers or financial account details were involved. Therefore, customers do not currently have evidence that they all need to replace payment cards. Still, review your bank statements and credit card activity. Watch for small charges that you do not recognize. Check your credit reports for new accounts or unfamiliar inquiries. Our guide to quiet signs of identity theft explains what can appear before larger problems surface. You may also consider an identity theft monitoring service if Brinks Home later confirms that sensitive personal information was exposed.
A credit freeze can make it harder for a criminal to open a new account in your name. You must place the freeze separately with Equifax, Experian and TransUnion. Adding or removing a freeze is free. However, a credit freeze cannot stop misuse of an existing bank or credit card account. Brinks Home has not confirmed that customers need to freeze their credit because of this incident. That recommendation could change if the company identifies exposed identity information.
Brinks Home tells customers not to respond to a suspicious message or click its links. However, the company also says not to delete the communication right away. Take screenshots and preserve the sender’s details. Save the date, time and phone number or email address involved. Then report the message using the contact information listed in the official Brinks Home incident FAQ. The company lists 469-391-4024 as a reporting number. You can also report online fraud or extortion attempts to the FBI’s Internet Crime Complaint Center at IC3.
Brinks Home says it will contact affected individuals if its investigation confirms that personally identifiable information was involved. However, criminals may send fake breach notices first. Compare any notice with information posted on the official Brinks Home cybersecurity update at brinkshome.com/cybersecurity-update .. Contact the company directly when something looks unusual. Do not pay anyone who threatens to release your information.
Brinks Home says it plans to provide more information once its investigation produces verified findings. “Protecting the information entrusted to Brinks Home remains a top priority, and we take our data security responsibilities very seriously. We appreciate the patience and understanding of our customers as we work through this process. We will provide additional updates as appropriate when more verified information becomes available,” the company told CyberGuy.
While Brinks Home serves more than 1 million customers nationwide, its recent cybersecurity incident shows that even a company trusted to protect homes can face digital vulnerabilities, despite assurances that alarm monitoring and system functionality continue without interruption. There are many other options in the market, whether you prefer a professionally installed system or a do-it-yourself one.
For reference, you can check out my guide on the best home security systems at Cyberguy.com , where I’ve listed four of my favorite options. You might also want to find out if your home insurance offers a discount for installing robust security protection.
IS YOUR SOCIAL SECURITY NUMBER ON THE DARK WEB?
The Brinks Home cyberattack feels personal because this company may hold information connected to your household. So far, Brinks Home has confirmed unauthorized access to part of its IT environment. It has not verified the hackers’ claim that they stole 4.9 million Salesforce records. The company says its alarm monitoring and security products continue to work normally. Customers do not need to disconnect their systems based on the information available now. The immediate danger may come from phishing. A criminal who knows your name or previous support issue can build a message that sounds convincing. Slow down when someone creates urgency. Contact Brinks Home through an official channel and never hand over a security code.
When a company is trusted to help protect your home, should it face a higher standard for guarding the personal information connected to it? Let us know by writing to us at CyberGuy.com.
Sign up for my FREE CyberGuy Report
Copyright 2026 CyberGuy.com. All rights reserved.
Source – https://www.foxnews.com/tech/brinks-home-data-breach-puts-1m-customers-alert