Renowned Security Company Breached by ShinyHunters – GadgetLad

ShinyHunters: The Intrusion Experts

A prominent name in residential and commercial physical security, Brinks Home, recently reported identifying unauthorized entry into a section of its IT infrastructure, an intrusion that ShinyHunters asserts it orchestrated to pilfer millions of records from the security provider’s Salesforce environment. Brinks Home has not disclosed the identity of the intruder or the specific compromised system, but has indicated that the responsible party has threatened to release information they claim to have acquired. “Brinks Home is diligently working to ascertain what information was involved and who might be impacted,” the company’s statement noted. “If the Company determines that personal data has been compromised, it will notify those individuals as necessary and appropriately.”

The Alarms Are Still Sounding

An FAQ section regarding the episode indicated that Brinks Home’s products and services weren’t impacted, according to the company’s current knowledge, meaning alarms and other security mechanisms should be functioning without problem.

Communication Lapse

While Brinks may not have provided much information and lacks any formal channel for media inquiries other than a LinkedIn message that went unanswered, the group claiming responsibility has publicly shared some specifics, and it is none other than ShinyHunters with yet another proclaimed Salesforce breach.

Millions of Records in Jeopardy

According to the leak monitoring organization Ransomware.live, ShinyHunters asserted that it had acquired over 4.9 million Salesforce records from Brinks Home “containing some PII.” The group issued a threat this week to leak the data as well as create “numerous irritating digital issues” if Brinks Home did not reach out by Thursday, July 30, to discuss a ransom payment. It remains unclear if Brinks Home has made contact with ShinyHunters; Brinks Home did not respond to inquiries, and contacts GadgetLad has for ShinyHunters seem to have changed, resulting in message and email denials.

Salesforce Vulnerability Exploited Once More

ShinyHunters has recently been an active Salesforce invader, with the group previously asserting earlier this year that it had stolen data from around 100 high-profile companies’ Salesforce environments. Salesforce has previously issued warnings that an unnamed known threat actor group was actively scanning for public-facing Salesforce instances and misusing misconfigured guest accounts to infiltrate.

The Brinks Association

Brinks Home is no longer affiliated with the larger Brinks brand, with The Brinks Company informing us that it divested the home security division in 2010. Brinks Home’s parent company, Monitronics, has declared bankruptcy twice since 2019; for the benefit of the customers, we hope their physical security services are more robust than their financial oversight and information security.

Overview

When Security Turns Into Insecurity

There you have it, folks. The security titan’s standing may be facing a more significant blow than an amateur fighter in a heavyweight bout. Let’s wish they enhance their data protections as effectively as they do their door locks, shall we?