ShinyHunters Claims Brinks Home Data Theft in Microsoft Entra Vishing Attack
A cybersecurity incident has been reported by Brinks Home, with attackers claiming to have breached the company through a Microsoft Entra voice phishing campaign targeting employee identities. The attack is attributed to the ShinyHunters extortion group, which allegedly stole over 1.1 million customer records from Salesforce, as well as employee PII and millions of customer support chat logs.
The incident follows a pattern of attacks by ShinyHunters against cloud-based platforms, including Canvas and Udemy earlier this year. The group's focus on SaaS environments highlights the importance of phishing-resistant authentication, stronger identity governance, and continuous cloud monitoring in defending against identity-based attacks.
ShinyHunters claims that the attack relied on social engineering rather than exploiting a software vulnerability, emphasizing the need for organizations to prioritize human-centric security measures. The incident serves as a reminder for companies to regularly test their incident response plans, particularly around identity and SaaS compromise.