JOHNSON CONTROLS, INC.
ent_5ceb1a2da5cb95ec8b8f23f4
Disclosures
17
State AG · SEC 10-K Item 1C · HHS OCR · SEC 8-K · 13 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
38,037
as filed · State AG TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- JOHNSON CONTROLS, INC.
- Normalized
- johnson controls— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 3LB2NG8VUULSCV2NO430
- SEC EDGAR CIK
- 0000833444
- Domain
- johnsoncontrols.com
- Corporate parent
- JOHNSON CONTROLS INTERNATIONAL PUBLIC LIMITED COMPANY— per GLEIF relationship records
Disclosure history (17)newest first
- New Hampshire State AGas victim2025-07-07
Johnson Controls filed a supplemental breach notification with the New Hampshire Attorney General on July 7, 2025, regarding an incident discovered on September 24, 2023. An unauthorized actor accessed systems between February 1, 2023, and September 30, 2023, exfiltrating personal information primarily of employees and contractors. The notification covers 1,611 New Hampshire residents. Remediation included password resets, MFA expansion, and enhanced monitoring.
- Texas State AGas victim2025-07-01
Johnson Controls based in Milwaukee, Wisconsin, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2023-09-24 and reported on 2025-07-01. 38,037 Texas residents were affected. Types of information involved: Other. Consumers were notified via Posted at company website or special website;U.S. Mail.
- Illinois State AGas victim2025-07-01
JOHNSON CONTROLS filed a data-breach notice with the Illinois Attorney General in July 2025 (case 25-07-287). The register records the breach as discovered on September 24, 2023. Personal information types reported: drivers license, financial account number, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Oregon State AGas victim2025-07-01
Johnson Controls reported a data breach to the Oregon Attorney General. The breach was reported on 2025-07-01. The breach occurred during 2/1/2023 - 9/30/2023. The breach was discovered on 9/24/2023. 3,829 individuals were affected. Notice was sent on 10/17/20236/30/2025.
- Iowa State AGas victim2025-06-30
Johnson Controls filed a supplemental security breach notification with the Iowa Attorney General on June 30, 2025, regarding 2,259 Iowa residents. The incident occurred between February 1, 2023, and September 30, 2023, when an unauthorized actor accessed systems and exfiltrated employee/contractor personal information. Johnson Controls discovered the breach on September 24, 2023, and has since enhanced security controls, reset passwords, and offered credit monitoring.
- California State AGas victim2025-06-30
Johnson Controls disclosed a cyber incident where an unauthorized actor accessed its network from February 1, 2023, to September 30, 2023. The company became aware of the incident on September 24, 2023. The actor exfiltrated personal information, including names and potentially credentials. Johnson Controls engaged third-party experts, terminated access, notified law enforcement, and is offering two years of credit monitoring to affected individuals.
- Delaware State AGas victim2025-06-30
Johnson Controls notified Delaware AG of a cyber incident discovered Sept 24, 2023. Unauthorized access occurred Feb 1–Sept 30, 2023, resulting in data exfiltration. Affected data includes names and other personal information. The company engaged forensic experts, terminated access, notified law enforcement, and offers two years of credit monitoring via Equifax.
- Washington State AGas victim2025-06-30
Johnson Controls filed a supplemental breach notification with the Washington AG on June 30, 2025, covering 4,903 residents. Unauthorized access occurred Feb 1–Sep 30, 2023. Johnson Controls discovered the incident on Sep 24, 2023. Data involved employee/contractor PII, including names and potentially credentials. Remediation included password resets, MFA expansion, and enhanced monitoring. 2-year credit monitoring offered.
- Montana State AGas victim2025-06-30
Johnson Controls notified Montana and other states of a cyber incident discovered September 24, 2023. Unauthorized actors accessed systems between Feb 1 and Sep 30, 2023, exfiltrating names and personal info. JCI engaged forensic experts, terminated access, notified law enforcement, and offered 2 years of credit monitoring via Equifax.
- Indiana State AGas victim2025-06-30
Johnson Controls reported a data breach to the Indiana Attorney General. The breach occurred on 2023-02-01 and was reported on 2025-06-30. 16,729 Indiana residents were affected.
- Vermont State AGas victim2025-06-30
Johnson Controls notified consumers of a cyber incident discovered in September 2023 involving unauthorized access to its network from February to September 2023. The incident resulted in the exfiltration of personal information, including names and credentials. Johnson Controls engaged third-party experts, terminated access, notified law enforcement, and offered two years of complimentary credit monitoring via Equifax.
- Illinois State AGas victim2025-06-01
JOHNSON CONTROLS filed a data-breach notice with the Illinois Attorney General in June 2025 (case 25-06-268). The register records the breach as discovered on September 24, 2023. Personal information types reported: ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- FEDERALSEC 10-K Item 1Cas victim2024-11-19
During the weekend of September 23, 2023, the registrant experienced a cybersecurity incident impacting its internal IT infrastructure and applications. The incident disrupted portions of business applications, causing lost and deferred revenues primarily tied to order processing and logistics, and disrupted certain billing systems, negatively impacting cash provided from continuing operations in Q1 fiscal 2024. The overall impact, net of insurance recoveries, was not material to full-year fiscal 2024 net income or cash flows.
- MONTANAHHS OCRas reporting2024-07-10
Johnson & Associates, Inc. reported to HHS on 2024-07-10 a Hacking/IT Incident affecting 4600 individuals. Breached information located on Network Server. PHI included names, addresses, and birthdates. The CE terminated its business relationship with the BA.
- FEDERALSEC 8-Kas victim2023-11-13
Johnson Controls International plc disclosed a cybersecurity incident involving unauthorized access and ransomware deployment by a third party. The incident was detected on September 23, 2023, causing disruptions to internal IT infrastructure and financial reporting systems. The company states the unauthorized activity has been contained, but investigation into data exfiltration remains ongoing. No specific count of affected individuals was provided.
- FEDERALSEC 8-Kas victim2023-09-27
Johnson Controls International plc reported a cybersecurity incident causing disruptions to portions of its internal IT infrastructure and applications. The company engaged external cybersecurity experts and is coordinating with insurers. Investigation and remediation are ongoing. No specific data types, affected counts, or attack vectors were disclosed in this initial Item 8.01 filing.
- South Carolina State AGas victim2023-09-24
Johnson Controls notified South Carolina and other jurisdictions of a cyber incident discovered September 24, 2023, involving unauthorized access to its network between February 1, 2023, and September 30, 2023. The actor accessed and exfiltrated personal information, including names and credentials. Johnson Controls engaged third-party experts, terminated access, notified law enforcement, and offered two years of complimentary credit monitoring via Equifax.