Circuit Wire — a daily news update from the Circuit.

Brinks Home, the Dallas alarm company that monitors more than a million properties, says it detected unauthorized access to part of its IT systems on July 20 and has been warned that the intruders plan to publish what they took. In a notice posted on its website, the company said it activated incident response procedures immediately and that alarm monitoring and system functionality continued without interruption.

The extortion group ShinyHunters claimed the attack earlier in the week. It told BleepingComputer that it got in on July 13 through a Microsoft Entra voice phishing call. In that method, a caller walks an employee through a Microsoft authentication or registration step, and the attacker ends up holding the account.

ShinyHunters says it took more than 4.9 million Salesforce records containing personal information. It claims more than 1.1 million rows came from the Contacts object, and more than 4,000 rows held employee data including full names, email addresses, job titles, and phone numbers. The group also claims more than 3.8 million customer support chat logs from the company's Brinks Care Cresta instance. BleepingComputer said it had not reviewed the data and could not verify those figures.

Brinks Home has not put a number on it. In an FAQ published alongside the notice, the company said it had "not yet confirmed exactly what information was involved or whose." Chief executive William Niles said the company is working with outside forensics experts. Brinks Home also warned that criminals may send fraudulent messages impersonating the company or others involved in the response, and told customers to delete suspicious messages rather than reply to them.

The company reports roughly $830 million in annual revenue and employs up to 1,500 people. It sells alarm panels, sensors, cameras, and smart home products to customers across the United States, Canada, and Puerto Rico.

The alarm sector has been hit before this year. ADT detected unauthorized access in April and said a limited set of customer data was taken, covering names, phone numbers, and addresses, with a smaller portion including dates of birth and partial Social Security numbers. ShinyHunters claimed more than 10 million Salesforce records from that intrusion, and Have I Been Pwned later listed 5.5 million unique email addresses tied to the breach. The same group listed Ernst & Young on its leak site on July 27, as we reported this week, claiming access through a supplier's support ticket system.

In each case the reported entry point sat away from the alarm hardware. ADT pointed to cloud environments, the Ernst & Young claim involved a third-party ticketing tool, and ShinyHunters describes a phone call to a single Brinks Home employee.

Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.

Spotted something we should cover? Send tips and feedback via circuit-magazine.com.

Keep Reading