ShinyHunters Claims Voice‑Phishing Breach of Brinks Home, Threatens to Leak 4.9 M Salesforce Records
What Happened — On July 13, 2026 ShinyHunters said it gained access to Brinks Home’s Microsoft Entra tenant via a voice‑phishing (vishing) call, harvested credentials, and exfiltrated over 4.9 million Salesforce records, employee PII, and 3.8 million support‑chat logs. Brinks Home confirmed a breach, activated its incident‑response plan, and warned that the stolen data could be published.
Why It Matters for Compliance & Audit Readiness
- Credential‑compromise via social engineering directly tests the effectiveness of SOC 2 CC6.1 (Logical Access) and CC6.2 (User Authentication) controls.
- Continuous evidence of security‑awareness training and phishing‑simulation results is essential to demonstrate due diligence during a SOC 2 audit.
- An extortion threat creates a “risk of data exposure” scenario that must be documented in the organization’s incident‑response and third‑party risk registers.
Who Is Affected — Residential‑security service providers, SaaS platforms handling customer data (e.g., Salesforce), and any organization that relies on Microsoft Entra for identity management.
Recommended Actions
- Verify and rotate all compromised Azure AD / Entra credentials; enforce MFA for privileged accounts.
- Conduct an immediate, organization‑wide security‑awareness refresher focused on voice‑phishing.
- Map the incident to SOC 2 access‑control criteria, capture training logs, and update your audit evidence repository.
Technical Notes — Attack vector: Microsoft Entra voice‑phishing (vishing). Stolen data: >4.9 M Salesforce “Contact” records, 4 K employee PII rows, 3.8 M chat logs from Cresta. No public CVE; the breach leveraged social engineering rather than a software flaw. Source: BleepingComputer