Troy Hunt's weekly update podcast from Vietnam discusses the Brinks Home data breach, criticizing the company's FAQ for failing to answer basic incident response questions, and outlines the typical extortion pattern involving vishing and OAuth.
<img src="https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2026/08/Splash-Template@1x_1.jpg" alt="Weekly Update 516: Live From Vietnam"><p>A little wind noise, a little connectivity flakiness, and a little lip-sync issues from YouTube, but look at that view! 🤩 Back to business, it's the Brinks Home FAQ I found most interesting this week. I mean, how do you write your own FAQ then fail to actually answer most of the questions?! Being conscious that they're the target of criminal extortion and are genuinely the victims here, I still struggle to grasp how simple incident response questions can be so lawyer-speaked as to remove all sensible meaning from the responses. But this is how these things tend to play out these days (speaking generically, yet to be seen fully for Brinks): hacker gets data by just calling up and asking for it (vishing -> OAuth), hacker demands money, hacker gets no money so dumps the data, company gets a gazillion class actions overnight and lawyers up to the hilt, customers get notified "where legally required" (which it usually isn't) 🤷‍♂️</p>
<!--kg-card-begin: html-->
<div><div style="width: 170px; display: inline-block; margin-right: 3px;"><a href="https://itunes.apple.com/au/podcast/troy-hunts-weekly-update-podcast/id1176454699?ref=troy-hunt"><img src="https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2018/05/Listen-on-Apple-Podcasts.svg" alt="Weekly Update 516: Live From Vietnam"></a></div><div style="width: 175px; display: inline-block; margin-right: 3px;"><a href="https://www.youtube.com/playlist?list=PL7LAAxaabizMAXnJe0s3xjQ30q12EVmjt&ref=troyhunt.com"><img src="https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2024/09/Watch-and-Listen-on-YouTube.svg" alt="Weekly Update 516: Live From Vietnam"></a></div><div style="width: 118px; display: inline-block; margin-right: 3px;"><a href="https://open.spotify.com/show/7jMtKFohdrw6qmz8AkLqit?ref=troy-hunt"><img src="https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2019/10/spotify.svg" class="kg-image" alt="Weekly Update 516: Live From Vietnam"></a></div><div style="width: 120px; display: inline-block;"><a href="https://omny.fm/shows/troy-hunt-weekly-update/playlists/podcast.rss?ref=troy-hunt"><img src="https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2018/07/Download-via-RSS.svg" alt="Weekly Update 516: Live From Vietnam"></a></div><iframe width="100%" height="480" src="https://www.youtube.com/embed/I9_A1rijY2I" title="YouTube video player" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen loading="lazy" spellcheck="false"></iframe></div>
<!--kg-card-end: html-->
# Weekly Update 516: Live From Vietnam
Source: [https://www.troyhunt.com/weekly-update-516/](https://www.troyhunt.com/weekly-update-516/)
A little wind noise, a little connectivity flakiness, and a little lip\-sync issues from YouTube, but look at that view\! 🤩 Back to business, it's the Brinks Home FAQ I found most interesting this week\. I mean, how do you write your own FAQ then fail to actually answer most of the questions?\! Being conscious that they're the target of criminal extortion and are genuinely the victims here, I still struggle to grasp how simple incident response questions can be so lawyer\-speaked as to remove all sensible meaning from the responses\. But this is how these things tend to play out these days \(speaking generically, yet to be seen fully for Brinks\): hacker gets data by just calling up and asking for it \(vishing \-\> OAuth\), hacker demands money, hacker gets no money so dumps the data, company gets a gazillion class actions overnight and lawyers up to the hilt, customers get notified "where legally required" \(which it usually isn't\) 🤷♂️
[](https://itunes.apple.com/au/podcast/troy-hunts-weekly-update-podcast/id1176454699?ref=troy-hunt)
[](https://www.youtube.com/playlist?list=PL7LAAxaabizMAXnJe0s3xjQ30q12EVmjt&ref=troyhunt.com)
[](https://open.spotify.com/show/7jMtKFohdrw6qmz8AkLqit?ref=troy-hunt)
[](https://omny.fm/shows/troy-hunt-weekly-update/playlists/podcast.rss?ref=troy-hunt)
[Weekly update](https://www.troyhunt.com/tag/weekly-update/)
Troy Hunt's weekly update covers his busy week with talks on 3D printing and infosec, data breaches, and IoT projects, focusing on security and data integrity topics.
Troy Hunt's weekly update covers a flurry of five data breaches loaded into Have I Been Pwned in just two days, including details on the Odido, KomikoAI, Quitbro, Lovora, and Provecho breaches.
Troy Hunt discusses the ongoing ShinyHunters data breaches and dumps, noting the criminality, organizational responses, and the seemingly endless cycle of new victims appearing, such as DentaQuest and BCD Travel.
Troy Hunt discusses the Origin Energy data breach in Australia, including the multi-faceted response from the company and hacker, and the ongoing risk of data leaks.