Johnson & Johnson, Inc.
ent_7e4b8c63c6d1680dd5b21e80
Disclosures
7
Leak Site · State AG · 6 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
3,225
nationwide · State AG ME
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- Johnson & Johnson, Inc.
- Normalized
- johnson johnson— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300G0CFPGEF6X2043
- SEC EDGAR CIK
- 0000200406
- Domain
- jjins.com
Disclosure history (7)newest first
- GLOBALLeak Siteas victim2026-07-31
Sector: Healthcare / Pharmaceutical | Data leaked: 1.9 GB
- GLOBALLeak Siteas victim2026-04-26
Johnson & Johnson Innovative Medicine (formerly known as Janssen Pharmaceuticals) is the pharmaceutical division of the American corporation Johnson & Johnson, specializing in the development and production of revolutionary medicines. The company focuses on creating treatments for the most complex diseases, transforming the future of healthcare.-CAR-T Research https://www.jnj.com/innovativemedicine/
- New Hampshire State AGas victim2024-10-22
Johnson & Johnson, Inc. notified the New Hampshire Attorney General of a network compromise detected on August 17, 2024. The incident impacted 10 New Hampshire residents, whose personal information (including SSN and DOB) may have been accessed. J&J engaged forensic experts, notified law enforcement, and provided credit monitoring services.
- Maine State AGas victim2024-10-18
Johnson & Johnson, Inc. reported an external system breach (hacking) on August 16, 2024, discovered on August 17, 2024. The incident affected 3,225 individuals nationwide, including 3 Maine residents. Personal information, potentially including government identifiers and basic PII, was compromised. J&J engaged third-party experts, notified law enforcement, and provided 12 months of credit monitoring via Equifax.
- Indiana State AGas victim2024-10-18
Johnson & Johnson Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-08-16 and was reported on 2024-10-18. 15 Indiana residents were affected. 3,225 individuals affected in total.
- Massachusetts State AGas victim2024-10-18
Johnson & Johnson, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-10-18. 106 Massachusetts residents were affected.
- Montana State AGas reporting2024-05-28
Cencora, Inc. notified Montana residents of a data security incident discovered on Feb 21, 2024, where data was exfiltrated. Affected info included names, addresses, DOB, and health diagnoses/medications. Cencora engaged law enforcement and forensic experts, provided 24 months of credit monitoring via Experian, and reinforced security protocols.
Subsidiary disclosures (8)filed by group companies
◈ These filings were made by or about subsidiaries of Johnson & Johnson, Inc. — not by Johnson & Johnson, Inc. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- New Hampshire State AGvia ETHICON, INC.2023-09-22
Butler Snow LLP notified the New Hampshire Attorney General on September 22, 2023, of a cybersecurity incident affecting three New Hampshire residents. The breach involved unauthorized access to systems storing personal information of individuals involved in pelvic mesh litigation against victim Ethicon, Inc. Butler Snow discovered suspicious activity on May 3, 2023, and notified law enforcement. Remediation included forensic investigation, credit monitoring via Experian, and enhanced employee training.
- Oregon State AGvia Johnson & Johnson Health Care Systems Inc.2023-09-15
Johnson & Johnson Health Care Systems Inc. (“Janssen”) reported a data breach to the Oregon Attorney General. The breach was reported on 2023-09-15. 4,142,215 individuals were affected.
- Washington State AGvia Johnson & Johnson Health Care Systems Inc.2023-09-05
Johnson & Johnson Health Care Systems Inc. (Janssen) notified Washington AG of unauthorized access to a third-party database managed by IBM supporting the Janssen CarePath patient platform. Discovered Aug 2, 2023, the breach affected ~53,970 WA residents. Data included names, contact info, DOB, health insurance, and medication data. No SSNs or financial accounts were involved. IBM remediated the vulnerability and offered credit monitoring.
- New Hampshire State AGvia AURIS HEALTH, INC.2021-01-29
Auris Health, Inc. notified the New Hampshire Attorney General's Office on January 27, 2021, regarding a phishing incident where an unauthorized third party accessed an employee's email account as of March 15, 2020. The breach potentially exposed the full names and Social Security numbers of two New Hampshire residents. Auris halted the activity, notified the affected individuals, and provided them with two years of complimentary credit and identity fraud monitoring through Equifax.
- Indiana State AGvia AURIS HEALTH, INC.2021-01-27
Auris Health, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2020-03-15 and was reported on 2021-01-27. 3 Indiana residents were affected.
- Massachusetts State AGvia AURIS HEALTH, INC.2021-01-27
Auris Health, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-01-27. 14 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGvia AURIS HEALTH, INC.2021-01-27
Auris Health, Inc. disclosed that an unauthorized actor accessed an employee's email account beginning in March 2020. The incident involved personal information including names, SSNs, tax IDs, passport numbers, health insurance numbers, health information, payment card info, and financial account numbers. Auris terminated access, conducted an investigation, and offered two years of credit monitoring via Equifax.
- Oregon State AGvia AURIS HEALTH, INC.2021-01-27
Auris Health, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2021-01-27. The breach occurred during 3/15/2020 - 8/14/2020. The breach was discovered on 8/14/2020. 4 individuals were affected. Notice was sent on 1/27/2021.