[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1vfcaU2S7wmDuMm0iZmfsj71OayJXPybrrIoM6fbgIE":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":25,"created_at":26,"published_at":27,"article":28,"tags":32,"podcasts":51},"b8c4bf8f-3091-47a4-a00b-492adfd0ba28","shinyhunters-breaches-brinks-home-via-voice-phishing-exposing-49m-records","f8279141-1f4d-460e-a7f0-de7b1400ab37","ShinyHunters Breaches Brinks Home via Voice Phishing, Exposing 4.9M Records","ShinyHunters gained initial access to Brinks Home's systems through a voice phishing (vishing) attack targeting Microsoft Entra credentials, demonstrating that even security-focused companies are vulnerable to social engineering. The seven-day gap between compromise (July 13) and discovery (July 20) allowed the attackers ample time to exfiltrate millions of Salesforce records containing sensitive customer PII and chat logs. This breach highlights the critical importance of phishing-resistant multi-factor authentication (MFA) and robust employee training specifically around telephone-based social engineering tactics. The scale of the data stolen — nearly 5 million customer records — creates lasting fraud and identity theft risks for affected individuals, amplifying the regulatory and reputational consequences for Brinks Home.","**Immediate actions:**\n- Replace SMS\u002Fvoice-based MFA with phishing-resistant alternatives such as FIDO2 hardware security keys or certificate-based authentication for all Microsoft Entra accounts.\n- Audit and restrict which roles have access to bulk Salesforce data exports or API queries to limit blast radius from compromised credentials.\n- Issue customer advisories warning of increased fraud, impersonation, and phishing attempts using their stolen PII.\n\n**Long-term improvements:**\n- Implement a formal vishing\u002Fsocial engineering awareness training program with simulated voice phishing exercises for all employees, especially those with privileged access.\n- Apply zero-trust principles by enforcing continuous identity verification and least-privilege access controls across CRM and cloud platforms.\n- Establish data minimization and retention policies in Salesforce to reduce the volume of sensitive records available to any single account or API integration.\n\n**Detection measures:**\n- Deploy user and entity behavior analytics (UEBA) to alert on anomalous bulk data access or exports from Salesforce and other data repositories.\n- Configure Microsoft Entra Identity Protection to flag and block risky sign-ins, including logins from unfamiliar locations or after suspicious MFA prompts.\n- Set a maximum acceptable detection window (e.g., 24–48 hours) for credential compromise events and test against it regularly through purple team exercises.",[12,13,14,15,16,17,18,19,20,21,22,23,24],"CIS Control 4: Secure Configuration of Enterprise Assets","CIS Control 6: Access Control Management","CIS Control 14: Security Awareness and Skills Training","CIS Control 16: Application Software Security","NIST SP 800-63B: Digital Identity Guidelines (Phishing-Resistant MFA)","NIST AC-2: Account Management","NIST AC-6: Least Privilege","NIST IR-6: Incident Reporting","NIST SI-4: System Monitoring","GDPR Article 32: Security of Processing","GDPR Article 33: Notification of a Personal Data Breach","NIST CSF DE.CM-1: Network Monitoring","ITIL: Incident Management & Problem Management","published","2026-07-30T18:21:12.028792+00:00","2026-07-30T18:21:11.893+00:00",{"id":7,"url":29,"slug":30,"title":31},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fshinyhunters-claims-brinks-home-breach-threatens-to-leak-stolen-data\u002F","shinyhunters-claims-brinks-home-breach-threatens-to-leak-stolen-data-c11337","ShinyHunters claims Brinks Home breach, threatens to leak stolen data",[33,39,45],{"id":34,"name":35,"slug":36,"description":37,"color":38},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":40,"name":41,"slug":42,"description":43,"color":44},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":46,"name":47,"slug":48,"description":49,"color":50},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]