This summer, criminals broke into Brinks Home. Not a house Brinks protects. The company itself. SecurityWeek reported the disclosure on August 3: an extortion group called ShinyHunters got into a customer-data system, demanded payment, did not get it, and published roughly 41 gigabytes of files. Have I Been Pwned, the breach-notification service run by security researcher Troy Hunt, loaded about 732,000 unique email addresses from the leak, along with names, home addresses, phone numbers, dates of birth, purchase histories, and partial credit card details, covering customers, sales leads, and Brinks staff alike.
The problem: the security company’s files are now public
Read that list again slowly, because this is not an ordinary data breach. Out in the open now is a directory of households that: have alarm systems, at these addresses, reachable at these numbers, who bought this equipment, on a card ending in these four digits.
To be fair to Brinks on the one point that matters most: by their account the attackers never touched the alarm systems themselves. Monitoring kept working. Nobody’s panic button went dead. What leaked is information about the families the company protects, and that is exactly the raw material the next scam is made of.
Why the usual advice falls short
Standard breach advice says change your password and move on. None of that helps here, because nothing that leaked can be changed. You cannot rotate your home address, your date of birth, or the fact that your house has an alarm system. For the pieces a criminal could turn into new accounts, the birth date and card fragments, freezing your credit is the standing answer. The rest does not expire; it settles into the pool of personal information already circulating about your family. And none of it leaked through your carelessness. It leaked from a vendor you paid, doing a thing you could not have prevented and cannot undo.
Waiting for the company to tell you what happened does not help much either. Brinks published a cybersecurity FAQ that Hunt reviewed with visible exasperation, asking how a company writes its own FAQ and then fails to answer most of the questions in it, and it promised notification only where legally required. He is careful to note that Brinks is genuinely the victim of a crime here, and that is true. It is also true that a family in that database cannot sit and wait for a letter that may never be required.
And here is the mechanic worth teaching your household, because it outlives this story: a breach like this does not rob you directly; it arms the person who will call you next. A scammer who knows your name, your address, your alarm brand, what you bought, and the last four digits of your card does not sound like a scammer. They sound like your account rep. “Confirming the card ending in 4821” used to be a sign the caller was real. After a breach like this one, it proves nothing at all. It is the same collapse that emptied scam messages of their old tells, arriving now by phone.
The guidance: four moves, one evening
- Look the family up. Go to haveibeenpwned.com and check each family email address. The Brinks Home breach is in there, and so are hundreds of others. Two minutes per address, free, no signup. If a family address appears, you are not in trouble. You are informed, which is the whole point.
- Call your alarm company and set the verbal password. Virtually every professional monitoring service supports a spoken codeword used to confirm it is really you when an alarm trips or changes are requested. If your household has one, change it. If you have never set one, set it tonight, and if your provider turns out not to offer one, ask for it. Do this whoever your provider is, not just Brinks. It is the single cheapest upgrade in home security. Then store it where your family keeps its real secrets: in the family’s Vault, with the same care as a banking PIN. Make sure the adults in the house all know it.
- Extend the bank rule to every company you pay. Your family may already have the rule for banks: if they call you, hang up and call back on the number on the card. Give the alarm company, and every other vendor, the same treatment. Any inbound call, text, or email about “your security system” gets one response: hang up, then dial the number printed on your bill or contract. Real companies survive that friction. Impostors do not.
- Retire “they knew my details” as proof of anything. Say it out loud at the dinner table, especially to the most trusting people in the house: from now on, a caller knowing our address, our equipment, or part of our card number means nothing. It is not evidence they are legitimate. After enough breaches, it is barely evidence they did their homework.
Quick reference
- A home-security vendor’s customer data leaked publicly: names, addresses, birth dates, phones, purchases, partial card numbers.
- The alarms kept working. The risk is impostors armed with your details, not a disabled system.
- Check every family email at haveibeenpwned.com.
- Set or change your monitoring center’s verbal password, whatever company you use.
- Inbound “your alarm company” contact = hang up, call the number on the bill.
- Knowing your details no longer proves a caller is real. Teach that sentence to the whole house.
The takeaway
There is a particular sting when the company you hired to make your family safer becomes the reason you are a target, and it is worth naming: you did the responsible thing, and it still leaked. That is not a reason for cynicism — it is a reason for design. A recoverable family does not assume its vendors will never fail. It assumes some of them will, and arranges things so that when the phone rings with a confident stranger who knows a little too much, the house already has its answer: we hang up, we dial the number we already have, and we never mistake a stranger’s homework for trust.
If you want to know where your family actually stands, the Recoverability Assessment takes about ten minutes and tells you plainly.