When you pay a company to help protect your home, you probably don't expect that company to become the target of a cyberattack.
But that's exactly what happened to Brinks Home, the residential security company that provides alarm systems and monitoring services.
The cybercriminal group ShinyHunters claims it broke into Brinks Home's systems and stole millions of records. The group reportedly obtained about 4.9 million records from the company's Salesforce environment and later published approximately 41 gigabytes of data after Brinks Home refused to pay a ransom.
Whenever criminals get their hands on a large pile of information, the obvious question is:
What's in it?
First, The Good News
Let's start with what did not happen. According to Brinks Home, the company's alarm monitoring systems and services were not compromised. In other words, this isn't a situation where someone hacked into the system and can now turn your alarm off from across the internet.
The company says the attackers accessed a portion of its IT systems and that it is investigating what information was involved and who may be affected. That's important. But it doesn't mean customers can simply forget about the incident.
The Data Is The Problem
The biggest concern with a breach like this isn't necessarily what criminals can do to the company's alarm systems. It's what they can do with information about the people who use them. Brinks Home has warned customers to be especially cautious about unsolicited emails, text messages and phone calls asking for personal information or account credentials.
That's good advice because stolen information has a nasty habit of becoming fuel for the next scam.
Imagine receiving a phone call from someone claiming to be from Brinks Home. They know your name. They know you're a customer. They may know information about your account. They tell you there's a problem with your security system and need you to confirm some information. Sounds legitimate, right? Maybe not.
This Is Where Scammers Get Creative
Cybercriminals don't necessarily need to steal your bank account password to cause trouble.
Sometimes they just need enough information to make you believe they are somebody they're not. And that's why "I don't think they got anything important" isn't necessarily a good response to a data breach.
Your name and contact information might not seem valuable. But combine that information with details about a company you do business with, and suddenly the scammer has a story.
Don't Let a Data Breach Turn Into a Scam
If you're a Brinks Home customer, be particularly skeptical of unexpected communications claiming to be from the company.
Watch for messages that:
- Ask you to confirm personal information.
- Request your password or account credentials.
- Ask for payment information.
- Tell you there is an urgent problem with your security system.
- Ask you to click a link to "secure" or "verify" your account.
- Ask you to install software or give someone remote access to your computer.
- Pressure you to act immediately.
And remember one of the oldest rules in the cybersecurity book: Don't click first and investigate later. If you receive a suspicious message, contact the company using a phone number or website you already know is legitimate. Don't use contact information provided in the suspicious message.
There's Another Lesson Here
This attack also highlights something that is easy to forget. Your information doesn't have to be stored by a bank or credit card company to be valuable. Companies that provide home security services can have plenty of information that criminals would love to get their hands on.
And even when the stolen data doesn't include the keys to your financial accounts, it can still be useful for impersonation and phishing.