Brinks Home breach: a phone call beat the security stack
ShinyHunters says it took Brinks Home's Salesforce data via an Entra vishing call — 1.1M customer rows and 3.8M chat logs. No CVE. Just a help desk that said yes.
The most recognizable name in physical security got its customer database taken by someone on the phone. Brinks Home confirmed unauthorized access to part of its IT systems after ShinyHunters claimed the breach. There was no zero-day in the chain. The Brinks Home breach started with a voice phishing call against Microsoft Entra, and it ended in Salesforce.
What actually happened
Per BleepingComputer, the attackers say they got in on July 13 using a Microsoft Entra vishing attack against employee accounts. Brinks Home discovered the intrusion on July 20 — roughly a week of dwell time. The group claims it pulled over 1.1 million rows of customer data out of Salesforce, plus employee data and more than 3.8 million customer support chat logs. The Register reports ShinyHunters set a July 30 deadline to negotiate before leaking.
Brinks Home has not confirmed the attackers' record counts. Its notification says the company is aware the material may be posted publicly and that it will notify affected individuals if personal information is confirmed involved. It also warned customers to be skeptical of unsolicited calls, texts, and emails asking for credentials — which is exactly how this started in the first place.
Why CRM security matters for your business
Every part of this attack is available to run against a ten-person company. Someone calls your help desk, sounds convincing, and gets an MFA reset or a device enrolled. That identity opens the identity provider. The identity provider opens everything federated to it — and for most small businesses, the richest thing federated to it is the CRM.
Note what was actually valuable here. Not a database of card numbers. Support chat logs — 3.8 million of them, by the attacker's count. Transcripts are the most under-secured customer data most businesses hold. They contain addresses, order histories, account details, sometimes credentials a customer typed in because they were frustrated. Nobody classifies them. Nobody sets a retention window on them. They just accumulate inside whatever helpdesk tool you bought in 2021.
Four fixes, none of which require a purchase. Put a hard verification step on your help desk — no MFA reset or device enrollment on a voice request alone, ever, including for executives. That rule has to be written down, because the whole attack is social pressure applied to someone who wants to be helpful. Set retention on chat and ticket logs; if you don't need three years of transcripts, don't keep three years of transcripts. Cap bulk export in your CRM so a single compromised account can't pull 1.1 million rows without tripping something. Alert on mass-read, not just on login anomalies — the attacker looked like a legitimate user the whole time.
The uncomfortable part: your detection window here was seven days at a company that sells security for a living.
Key takeaways
- Attackers claim they breached Brinks Home on July 13 via a Microsoft Entra vishing call; the company found it July 20 and confirmed a compromise July 31
- ShinyHunters claims 1.1M+ rows of Salesforce customer data, employee data, and 3.8M+ support chat logs — figures Brinks has not confirmed
- The entry point was a phone call to a help desk, not a software vulnerability — patching would not have stopped this
- Write down a no-voice-only-resets rule, set retention on support transcripts, cap bulk CRM exports, and alert on mass-read behavior
We design integrations assuming one account will eventually be taken — scoped service identities, export limits, and logs that show what got read. If your CRM and helpdesk are wide open behind a single sign-on, let's walk your access map. Or see how we build systems you can audit.
Sources: BleepingComputer, The Register.
- #vishing
- #salesforce
- #crm-security
- #identity
- #data-breach
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Teams vishing to ransomware in 17 hours: lock external chat
Sophos tracked a Microsoft Teams vishing campaign against dozens of North American firms. Fake IT helpdesk calls, then Chaos ransomware. Restrict external Teams access.
Read itCosmosEscape: your cloud provider is shared fate
Wiz found a platform-wide key that unlocked any Azure Cosmos DB account. Nothing for you to patch — which is exactly why it should change how you pick vendors.
Read it