Johnson & Johnson
ent_019e215a9ed09f8f5ae49a37cff12e7b
Disclosures
6
Leak Site · SEC 10-K Item 1C · State AG · 5 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
3,225
nationwide · State AG IN
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- Johnson & Johnson
- Normalized
- johnson johnson— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300G0CFPGEF6X2043
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (6)newest first
- GLOBALLeak Siteas victim2026-07-31
Sector: Healthcare / Pharmaceutical | Data leaked: 1.9 GB
- GLOBALLeak Siteas victim2026-04-26
Johnson & Johnson Innovative Medicine (formerly known as Janssen Pharmaceuticals) is the pharmaceutical division of the American corporation Johnson & Johnson, specializing in the development and production of revolutionary medicines. The company focuses on creating treatments for the most complex diseases, transforming the future of healthcare.-CAR-T Research https://www.jnj.com/innovativemedicine/
- FEDERALSEC 10-K Item 1Cas victim2026-02-11
Item 1C of Form 10-K discloses the registrant's cybersecurity risk management and governance policies. The Company states it is not aware of any cybersecurity incident that has had or is reasonably likely to have a material impact on its business or operations. No specific breach, incident date, or affected data types are reported.
- 🦞Maine State AGas victim2024-10-18
Johnson & Johnson, Inc. reported an external system breach (hacking) that occurred on August 16, 2024, and was discovered the following day. The breach affected 3 Maine residents. The company provided 12 months of credit monitoring and identity theft protection services through Equifax.
- 🏎️Indiana State AGas victim2024-10-18
Johnson & Johnson Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-08-16 and was reported on 2024-10-18. 15 Indiana residents were affected. 3,225 individuals affected in total.
- 🐻California State AGas reporting2024-05-28
Cencora, Inc. notified California residents that data from its information systems was exfiltrated on February 21, 2024. The incident potentially affected personal information including names, addresses, dates of birth, health diagnoses, and medications. Cencora engaged law enforcement and cybersecurity experts, contained the incident, and is offering 24 months of credit monitoring to affected individuals.
Subsidiary disclosures (3)filed by group companies
◈ These filings were made by or about subsidiaries of Johnson & Johnson — not by Johnson & Johnson itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- ⛰️New Hampshire State AGvia ETHICON, INC.2023-09-22
Butler Snow LLP notified the New Hampshire Attorney General on September 22, 2023, of a cybersecurity incident affecting three New Hampshire residents. The breach involved unauthorized access to systems storing personal information of individuals involved in pelvic mesh litigation against victim Ethicon, Inc. Butler Snow discovered suspicious activity on May 3, 2023, and notified law enforcement. Remediation included forensic investigation, credit monitoring via Experian, and enhanced employee training.
- 🐻California State AGvia AURIS HEALTH, INC.2021-01-27
Auris Health, Inc. disclosed that an unauthorized actor accessed an employee's email account beginning in March 2020. The incident involved personal information including names, SSNs, tax IDs, passport numbers, health insurance numbers, health information, payment card info, and financial account numbers. Auris terminated access, conducted an investigation, and offered two years of credit monitoring via Equifax.
- 🦫Oregon State AGvia AURIS HEALTH, INC.2021-01-27
Auris Health, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2021-01-27. The breach occurred during 3/15/2020 - 8/14/2020. The breach was discovered on 8/14/2020. 4 individuals were affected. Notice was sent on 1/27/2021.