The Register Home Page

back to article The most famous brand in physical security got pwned by ShinyHunters

A leading name in home and business physical security, Brinks Home, recently said it identified unauthorized access to a portion of its IT systems, an intrusion ShinyHunters claims it carried out to steal millions of records from the security provider's Salesforce instance. Brinks Home hasn’t named the intruder or identified the …

  1. iron

    The most famous brand in physical security

    Was expecting Chubb or Yale, who the hell are Brinks Home?

    Never heard of them.

    1. Apprentice of Tokenism

      Re: The most famous brand in physical security

      It‘s a Yank outfit. Not sure why it is assumed that everybody in the world knows companies only relevant in the US.

      1. Anonymous Coward
        Anonymous Coward

        Re: The most famous brand in physical security

        It's because El Reg was "Cadbury'd"...Americans thought they could buy culture, then promptly removed it and replaced it with their homogenised naffness assuming the prestige would still stick.

        American culture is like fucking teflon, when you apply as a layer on something, it repels everything.

        1. Esso

          Re: The most famous brand in physical security

          As a born and raised Yank, this is undeniably true.

        2. Anonymous Coward
          Anonymous Coward

          Re: The most famous brand in physical security

          Is The Register actually American-owned, and did the change in direction have anything to do with a takeover?

          I thought the problem was that, from the late 2010s onwards, they'd clearly started trying to take advantage of their increasing US audience by focusing on them as the default audience. (*)

          And, to that end, they visibly toned down the "British" humour or any signs of "Britishness" and intentionally adopted the same blinkered US-by-default mentality that most of their US rivals already took for granted- because that's how Americans think- including the assumption that everyone reading would already understand parochial US-centric language or references.

          (*) Something that culminated in the switch from the old ".co.uk" domain redirecting to the now-standard "The Register.com" in May 2020. Which happened- coincidentally or not- when everyone was distracted by the first wave of Covid and lockdown and probably attracted less attention or fuss than it would have done otherwise.

          1. Blazde Silver badge

            Re: The most famous brand in physical security

            El Reg still owned by Brits (albeit one has moved to Monaco) but claims a US HQ now (UK office presumably just a postbox) and I think all the steady journalists are US-located, mostly long-time Yanks rather than relocated Brits. You can see the articles that get published in the morning in European timezones are less 'newsy' pre-written like the PWNED column which has a routine on-the-hour publication time (0800 UTC currently) and the fresh news articles don't begin until America wakes up.

            Even in the US is Brinks Home *the* leading brand in physical security? Ring? Allied Universal? Master Lock? Blackwater (no longer goes by that name but I'm sure it's more well-known as that)? Lockheed Martin..? Glock?

    2. Anonymous Coward
      Anonymous Coward

      Re: The most famous brand in physical security

      I was expecting an actual famous brand as well. I guess these guys are famous for being hacked.

  2. JimmyPage Silver badge

    The most famous brand in physical security

    Well if you count the Brinks Mat robbery then you are probably right.

    1. just4this Bronze badge

      Re: The most famous brand in physical security

      A “Beware of The Dog” sign is probably more effective than Yale,

    2. Anonymous Coward
      Anonymous Coward

      Re: The most famous brand in physical security

      That was the first thing *I* thought about when I heard the "Brinks" name.

      Maybe Brinks is better-known to the yank audience The Register aims at nowadays, but I suspect that to most of the UK audience they're not "famous" for anything other than that failure to stop tens of millions of quid of gold et al being stolen from their warehouse forty-plus years ago.

      1. Blazde Silver badge

        Re: The most famous brand in physical security

        I'd assumed this was coincidence but, according to Wikipedia the 'Brinks Home' brand was actually created and still owned by *that* Brinks, even though a different company licenses it currently. Jeez. Maybe they are the most (in)famous after all.

        1. Anonymous Coward
          Anonymous Coward

          Re: The most famous brand in physical security

          Haven't heard of "Brinks Home" at all. Do they even operate in the UK or is this just another name "famous" only in the US?

          1. Blazde Silver badge

            Re: The most famous brand in physical security

            This Brinks: https://brinksglobal.com/

            It's much, much bigger and much, much older than the tiny company that licenses the 'Brink's Home' brand.

            Brinks may well have the honour of being the target of the most high-value heists, for some definition of 'high-value heist'.

      2. David Hicklin Silver badge

        Re: The most famous brand in physical security

        And after watching the two drama documentary programs on TV I was slightly amazed that hardly any of the gold was recovered.

        Oh we do know where most of it is, just look closely at any gold purchased since shortly after the raid....

        1. Blazde Silver badge

          Re: The most famous brand in physical security

          You can look Gordon Parry up on Facebook, living in Florida. No ***** given.

          (I don't know what to think. They say the problem with most criminals is they don't know when to stop. If he made enough to live off, did his 10 years, avoided getting deleted in the subsequent gang war, stashed the money, recovered it, avoided losing it in a messy divorce, invested it well, stayed clean, declined future jobs and didn't get draw into the Hatton Garden party... at some point you have to shrug. I mean it's definitely not right, but in some weird sense it's still earned).

  3. Pete 2 Silver badge

    Double speak

    > to negotiate a ransom payment

    You'd think by now the hackers would have rebranded and be talking about discussing with their clients the terms of an enhanced security fee

    1. Yet Another Anonymous coward Silver badge

      Re: Double speak

      For now, at least, the hackers are honest criminals - not MBAs

  4. Edward Jazzhands

    These breaches will only increase in frequency for as long as there's no consequences when they happen. From the perspective of the soulless corporation, why would they care? Most people will never hear about it so it doesn't affect their sales. The government doesn't seem to care, if there is a fine it's a tiny slap on the wrist. We are headed towards a dystopian hellhole where these kinds of breaches are a regular daily occurrence and nobody cares or does anything.

    1. VicMortimer Silver badge

      The ONLY thing that will ever stop ransomware is to make it a crime to pay ransom.

      Lock up a few CEOs for paying and the money will stop. If the money stops, the ransomware will stop.

      1. vtcodger Silver badge

        Words to Live By

        "Explanations exist; they have existed for all time; there is always a well-known solution to every human problem — neat, plausible, and wrong." H.L.Menken

        Punishing the victim because you/we are too obtuse to deal with the actual problem -- the @#$!% Internet is an attractive nuisance with many virtues and one enormous downside, it's hopelessly insecure -- is not likely to solve any problem. It just adds another layer of grief.

        1. Alumoi Silver badge

          Re: Words to Live By

          Wrog. If the CEOs and some major shareholders go to jail you will be amazed how quickly the security will be tightened.

        2. Anonymous Coward
          Anonymous Coward

          Re: Words to Live By

          If they're handing a large wad of cash to a criminal, their behavior is at least borderline-criminal itself; at that point, they're aiding and abetting a known criminal, not acting like an innocent victim.

          Besides, there's a hefty practical side to this. If a company knows their execs face jailtime or a major fine (think 100x the ransom) if they pay a ransom, they'll tend not to. This removes the main incentive for the ransomware groups to break in in the first place. While it may be possible to sell stolen data, that's likely much less lucrative than a ransom. So, criminalize the paying of the ransom and there will be fewer attacks.

      2. Throatwarbler Mangrove Silver badge
        Thumb Up

        I'm not sure if locking up the CEOs will help, but let's give it a shot for science!

    2. ecofeco Silver badge
      Thumb Up

      They've already BEEN increasing in frequency. For years now.

      If you mean it will only get worse, then yes, absolutely.

  5. Taliesinawen Bronze badge
    Terminator

    How Brinks got pwned

    “In a conversation with BleepingComputer, ShinyHunters said that they breached Brinks Home on July 13 in a Microsoft Entra voice phishing (vishing) attack.”

    1. Anonymous Coward
      Anonymous Coward

      Re: How Brinks got pwned

      ...and thus proving no matter how much you spend on fancy security devices, procedures and appliances...you're only as secure as the most gullible dickhead in the company.

  6. sarusa Silver badge
    Devil

    Well, sure, maybe kind of famous in the US, but...

    I've dealt with Brinks employees before and they were total clowns.

    As usual, being one of the best known just means you have the best schmoozing and most sociopathic execs who are (probably) buying potential and current customer company execs the most drugs and booze and whores, not that you're any good at what you're doing.

    1. nobody who matters Silver badge

      I'm not sure that it is even as much as that - in my experience, most corporate incompetence can be adequately explained by the 'Peter Principle'; and they are incompetent and incapable to the point that those above are unable to see the shortcomings of those below.

  7. Will Godfrey Silver badge
    Boffin

    I'm upset.

    I was going to comment, but found previous commentards have covered every single point I would have wanted to make.

    I guess that leaves me with... <AOL_MODE = ON> Me Too! <AOL_MODE = OFF>

  8. TheCobbler

    This is the Lock Picking Lawyer and today we are going to look at Brinks

    Immediately thought of this:

    https://youtu.be/9Ea4pYtbuJA?si=hxbhdyCYk7tMciIJ

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon