JOHNSON CONTROLS, INC.
ent_019ebcfe6738d3ee9f176bd9c03a4e1b
Disclosures
14
State AG · SEC 10-K Item 1C · SEC 8-K · 12 jurisdictions
Incidents
3
filings grouped by incident
Max affected reported
38,037
as filed · State AG TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- JOHNSON CONTROLS, INC.
- Normalized
- johnson controls— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 3LB2NG8VUULSCV2NO430
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (14)newest first
- ⛰️New Hampshire State AGas victim2025-07-07
Johnson Controls filed a supplemental breach notification with the New Hampshire Attorney General on July 7, 2025, regarding an incident discovered on September 24, 2023. An unauthorized actor accessed systems between February 1, 2023, and September 30, 2023, exfiltrating personal information primarily of employees and contractors. The notification covers 1,611 New Hampshire residents. Remediation included password resets, MFA expansion, and enhanced monitoring.
- ⭐Texas State AGas victim2025-07-01
Johnson Controls based in Milwaukee, Wisconsin, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2023-09-24 and reported on 2025-07-01. 38,037 Texas residents were affected. Types of information involved: Other. Consumers were notified via Posted at company website or special website;U.S. Mail.
- 🦫Oregon State AGas victim2025-07-01
Johnson Controls reported a data breach to the Oregon Attorney General. The breach was reported on 2025-07-01. The breach occurred during 2/1/2023 - 9/30/2023. The breach was discovered on 9/24/2023. 3,829 individuals were affected. Notice was sent on 10/17/20236/30/2025.
- 🌽Iowa State AGas victim2025-06-30
Johnson Controls, a manufacturing sector entity reported a data breach to the Iowa Attorney General. The breach was reported on 2025-06-30.
- 🐻California State AGas victim2025-06-30
Johnson Controls disclosed a cyber incident where an unauthorized actor accessed its network from February 1, 2023, to September 30, 2023. The company became aware of the incident on September 24, 2023. The actor exfiltrated personal information, including names and potentially credentials. Johnson Controls engaged third-party experts, terminated access, notified law enforcement, and is offering two years of credit monitoring to affected individuals.
- 💎Delaware State AGas victim2025-06-30
Johnson Controls notified Delaware AG of a cyber incident discovered Sept 24, 2023. Unauthorized access occurred Feb 1–Sept 30, 2023, resulting in data exfiltration. Affected data includes names and other personal information. The company engaged forensic experts, terminated access, notified law enforcement, and offers two years of credit monitoring via Equifax.
- 🌲Washington State AGas victim2025-06-30
Johnson Controls, a business sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2023-09-24 and filed notice on 2025-06-30. 4,903 Washington residents were affected. 645 days elapsed between awareness and notification. 235 days to identify the breach. 6 days to contain the breach.
- 🦬Montana State AGas victim2025-06-30
Johnson Controls reported a data breach to the Montana Attorney General. The breach was reported on 2025-06-30. The breach occurred from 02/01/2023 to 09/30/2023. 639 Montana residents were affected.
- 🏎️Indiana State AGas victim2025-06-30
Johnson Controls reported a data breach to the Indiana Attorney General. The breach occurred on 2023-02-01 and was reported on 2025-06-30. 16,729 Indiana residents were affected.
- 🍁Vermont State AGas victim2025-06-30
Johnson Controls notified consumers of a cyber incident discovered in September 2023 involving unauthorized access to its network from February to September 2023. The incident resulted in the exfiltration of personal information, including names and credentials. Johnson Controls engaged third-party experts, terminated access, notified law enforcement, and offered two years of complimentary credit monitoring via Equifax.
- FEDERALSEC 10-K Item 1Cas victim2024-11-19
During the weekend of September 23, 2023, the registrant experienced a cybersecurity incident impacting its internal IT infrastructure and applications. The incident disrupted portions of business applications, causing lost and deferred revenues primarily tied to order processing and logistics, and disrupted certain billing systems, negatively impacting cash provided from continuing operations in Q1 fiscal 2024. The overall impact, net of insurance recoveries, was not material to full-year fiscal 2024 net income or cash flows.
- FEDERALSEC 8-Kas victim2023-11-13
Johnson Controls International PLC disclosed a cybersecurity incident detected on September 23, 2023, involving unauthorized access and ransomware deployment. The Company engaged cybersecurity experts, restored impacted systems, and contained the activity. The incident caused disruptions to financial reporting systems, delaying the fiscal 2023 10-K filing. Investigation into data exfiltration and impact is ongoing.
- FEDERALSEC 8-Kas victim2023-09-27
Johnson Controls International plc reported a cybersecurity incident disrupting internal IT infrastructure on September 27, 2023. The company engaged external cybersecurity experts and insurers, executing an incident management plan. The investigation is ongoing to determine the scope of impacted information and potential data compromise.
- 🌴South Carolina State AGas victim2023-09-24
Johnson Controls notified South Carolina and other jurisdictions of a cyber incident discovered September 24, 2023, involving unauthorized access to its network between February 1, 2023, and September 30, 2023. The actor accessed and exfiltrated personal information, including names and credentials. Johnson Controls engaged third-party experts, terminated access, notified law enforcement, and offered two years of complimentary credit monitoring via Equifax.