Troy Hunt's weekly video update recorded from Vietnam covers the Brinks Home security incident. The company published an FAQ that fails to actually answer key questions about the breach. The attack pattern described: a hacker used vishing combined with OAuth to obtain data, demanded a ransom, received none, then dumped the data publicly. Brinks is now facing class action lawsuits and has lawyered up, notifying customers only 'where legally required.' Hunt reflects on how this pattern of corporate incident response — heavy on legal language, light on transparency — has become the norm.

1m read timeFrom troyhunt.com
Post cover image

Questions this post answers

How did the Brinks Home data breach happen?

The Brinks Home breach followed a vishing-to-OAuth attack chain: a hacker called up and socially engineered their way into obtaining data via OAuth, then demanded a ransom. When no payment was made, the hacker dumped the data publicly. Brinks subsequently faced class action lawsuits and notified customers only where legally required. Teams handling breach response and disclosure decisions track real-world incident patterns on daily.dev.

113 Impressions