
On Aug. 6, 2026, Denise Masi filed a class action lawsuit against BH Security LLC, d/b/a Brinks Home, in the U.S. District Court for the Northern District of Texas.
The lawsuit alleges Brinks Home failed to secure the personal information of tens of thousands of current and former customers and employees, leading to a cyberattack that exposed Social Security numbers and other sensitive data.
The breach
Around July 22, 2026, Brinks Home reported it experienced a cyberattack on its computer networks. The complaint claims the data breach compromised files containing sensitive personal data belonging to Masi and at least tens of thousands of other people, including Social Security numbers and government-issued identification numbers.
The complaint alleges Brinks Home didn't encrypt the compromised data and that the stolen information is now available on the dark web. Reporting suggests a hacker group calling itself ShinyHunters is responsible with the group saying it stole nearly 5 million records from Brinks Home's Salesforce environment.
Brinks Home said its alarm monitoring services remained unaffected and it did not find evidence the breach compromised personal information.
Alleged security failures
The lawsuit claims Brinks Home failed to maintain an adequate data security system despite breaches that dominated headlines at companies like Equifax, Marriott and Yahoo, arguing the company should have foreseen an attack.
The filing alleges Brinks Home failed to patch known vulnerabilities, monitor its networks for intrusions, enforce basic credential hygiene among employees and third parties and train staff on handling sensitive information. It also claims Brinks Home held personal data longer than necessary, including information belonging to former customers and employees who no longer had a relationship with the company.
The proposed class action alleges Brinks violated Section 5 of the Federal Trade Commission Act, which requires companies to use reasonable measures to protect the data they collect. The complaint argues that violating this standard amounts to negligence under the law.
The legal claims
The Brinks data breach class action lawsuit brings four claims against Brinks Home:
- Negligence, claiming Brinks Home owed a duty to protect personal data and breached that duty by failing to use reasonable security measures
- Breach of implied contract, contending customers and employees reasonably expected Brinks Home to keep their information secure in exchange for providing it
- Unjust enrichment, pleaded as an alternative claim, asserting Brinks Home saved money by using cheaper security measures while customers and employees bore the resulting risk
- Declaratory judgment, asking the court to declare Brinks Home has an ongoing duty to secure and notify affected individuals about their data and that it continues to fall short of that duty
The proposed class covers everyone whose personal information Brinks Home maintained and the cyberattack compromised, a group the filing puts in the tens of thousands with an amount in controversy exceeding $5 million. Masi and the class seek class certification, compensatory and punitive damages, credit monitoring, injunctive relief and attorneys' fees.
What this means for Brinks Home customers
As of this writing, the case has no settlement, no claims process and no payout available. Customers or employees who believe the breach exposed their information can review their credit report, place a fraud alert or freeze their credit while the litigation continues.
.png)







.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)



