HackingMulti-Stage ChainData ExfiltratedIDENTITY_BASICCREDENTIALSLowContained
JOHNSON CONTROLS, INC.
bd_fa9193fcd908cd4f · schema v1 · pii pii-v1
Full breach record for JOHNSON CONTROLS, INC. →Johnson Controls notified consumers of a cyber incident discovered in September 2023 involving unauthorized access to its network from February to September 2023. The incident resulted in the exfiltration of personal information, including names and credentials. Johnson Controls engaged third-party experts, terminated access, notified law enforcement, and offered two years of complimentary credit monitoring via Equifax.
Vermont clock✗ VT AG >45 bday22 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_26c3ced2ff25f41eIowa State AGfiled 2025-06-30Verified
- bd_5284e02cf7bdc3abCalifornia State AGfiled 2025-06-30Verified
- bd_5dff2cf2bc9347e1Delaware State AGfiled 2025-06-30Verified
- bd_b3d1bc45d4933741Montana State AGfiled 2025-06-30Candidate
Show 1 more filing ↓Show fewer ↑
- bd_ef10c9b1f9661892Indiana State AGfiled 2025-06-30Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-06-30-johnson-controls-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 30, 2025
- Raw hash
- 756bff98dff12d40f0ff2a4019ab11cfcb1e36f0f2d05d85bccf2ae0d8b1067d
Reporting entity
- Name
- JOHNSON CONTROLS, INC.norm: johnson controls
Victim entity
- Name
- JOHNSON CONTROLS, INC.norm: johnson controls
Incident
- Discovered
- Sep 24, 2023
- Materiality determined
- Sep 27, 2023
- Notification sent
- Jun 30, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 22 months(645 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.