FEDERALItem 8.01 · voluntaryMalwareRansomwareStolen CredentialsData ExfiltratedData EncryptedCustomer Data InvolvedEmployee Data InvolvedPIICREDENTIALSIPLowContained
JOHNSON CONTROLS, INC.
bd_b13de6d7c76d8c02 · schema v1 · pii pii-v1
Full breach record for JOHNSON CONTROLS, INC. →Johnson Controls International PLC disclosed a cybersecurity incident detected on September 23, 2023, involving unauthorized access and ransomware deployment. The Company engaged cybersecurity experts, restored impacted systems, and contained the activity. The incident caused disruptions to financial reporting systems, delaying the fiscal 2023 10-K filing. Investigation into data exfiltration and impact is ongoing.
SEC clockMateriality determined Nov 13, 2023 → Filed Nov 13, 20230d ✓ SEC 4-day OK7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_ff1220a37a34d710SEC 8-Kfiled 2023-09-27(47d gap)Candidate
- bd_293f6ff8a18cb042South Carolina State AGfiled 2023-09-24(50d gap)Candidate
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/833444/000083344423000038/
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Nov 13, 2023
- Raw hash
- 40d57f56c52fec7b93c345cd36fb13b4842162470fccc4a8821f46852f2c2bb2
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- JOHNSON CONTROLS, INC.norm: johnson controls
- SEC CIK
- 0000833444
Victim entity
- Name
- JOHNSON CONTROLS, INC.norm: johnson controls
- SEC CIK
- 0000833444
Incident
- Discovered
- Sep 23, 2023
- Materiality determined
- Nov 13, 2023
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIICREDENTIALSIP
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 7 weeks(51 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 0d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Nov 13, 2023→ Filed: Nov 13, 20230d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.