On July 13, 2026, attackers linked to the extortion group ShinyHunters placed a voice-phishing call to a Brinks Home employee, impersonating internal IT to walk the target through an authentication flow that handed over a valid session. The group claims it used the access to exfiltrate more than 4.9 million Salesforce customer and employee records and roughly 3.8 million customer support chat logs from Brinks Home’s Cresta AI-powered contact-center platform. Brinks Home confirmed unauthorized access to part of its IT environment, contained the intrusion, and engaged outside cybersecurity experts, though it has not verified the full scope the attackers claim.