Brinks Home Data Breach (August 2026)
Brinks Home, the Dallas-based alarm monitoring company, was breached in July 2026, exposing 732,162 email addresses along with names, phone numbers, physical addresses, dates of birth, purchase records and partial credit card data.
- Organization
- Brinks Home
- Sector
- Other
- Country
- United States, TX
- Incident date
- July 13, 2026
- Disclosed
- August 8, 2026
- Records affected
- 732,000
- Attack type
- Social engineering
- Threat actor
- ShinyHunters
- Status
- Confirmed
- Dates of birth
- Email addresses
- Names
- Partial credit card data
- Phone numbers
- Physical addresses
- Purchases
- Attackers gain access to Brinks Home systems, as reported by BleepingComputer.
- Brinks Home identifies the intrusion and activates its incident response procedure, per the company statement quoted by BleepingComputer.
- Have I Been Pwned loads the verified records into its database, per the listing.
What Happened
Brinks Home was targeted in a ShinyHunters extortion campaign that the Have I Been Pwned entry dates to July 2026. According to BleepingComputer, the intrusion began on July 13, 2026, and the company identified it a week later, on July 20. Brinks Home said it activated its incident response procedure on discovery, in a statement quoted by BleepingComputer, and that alarm monitoring and system functionality were not affected for customers.
The data the group later published contains 732,162 unique email addresses, per the Have I Been Pwned entry, along with names, phone numbers, physical addresses and dates of birth belonging to leads, customers and Brinks staff. The listing states that the set also includes purchases from Brinks and partial credit card data, specifically the last four digits, the card type and the expiry date. Brinks Home acknowledged the incident and the risk of disclosure in its own notice, per the same entry.
BleepingComputer reported that initial access came from a Microsoft Entra voice phishing call aimed at an employee, and that ShinyHunters claimed to have taken more than a million customer contact records from Salesforce along with employee details and customer support chat logs. BleepingComputer noted that it had not independently verified those volume claims. Have I Been Pwned loaded the verified records on August 8, 2026, after the group had already published the files.
What Was Exposed
7 classes of data across 732,162 records, per Have I Been Pwned: Brinks Home breach entry: dates of birth, email addresses, names, partial credit card data, phone numbers, physical addresses and purchases.
A name, date of birth, home address, phone number and purchase history in one file give a caller everything needed to pose convincingly as Brinks Home, and the last four card digits make that pitch sound already verified.
What to Do If You Are Affected
The full sequence, and what to do in what order, is in what to do after a data breach.
What Is Not Known Yet
Brinks Home has not said how many people it will notify or which categories of customer, lead and employee records its forensic review confirmed as taken. No source has said whether the voice phishing call reached more than one employee account.
Sources

Daniel Reyes
Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.
Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.