Clustered 6 filings across 6 jurisdictions · filed Jun 30, 2025. View entity profile → Other incidents for this victim →
incident inc_8ff64b50720047bb · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
CA DE IA IN MT VT
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
all State AG
Earliest sighting first · deep chronology in Litigation Timeline
Feb 1, 2023 → Sep 30, 2023
When the intrusion reportedly occurred, per the linked filings
Sep 24, 2023
Reported by CALIFORNIA AG, DELAWARE AG, VERMONT AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Johnson Controls, a manufacturing sector entity reported a data breach to the Iowa Attorney General. The breach was reported on 2025-06-30.
Johnson Controls disclosed a cyber incident where an unauthorized actor accessed its network from February 1, 2023, to September 30, 2023. The company became aware of the incident on September 24, 2023. The actor exfiltrated personal information, including names and potentially credentials. Johnson Controls engaged third-party experts, terminated access, notified law enforcement, and is offering two years of credit monitoring to affected individuals.
Johnson Controls notified Delaware AG of a cyber incident discovered Sept 24, 2023. Unauthorized access occurred Feb 1–Sept 30, 2023, resulting in data exfiltration. Affected data includes names and other personal information. The company engaged forensic experts, terminated access, notified law enforcement, and offers two years of credit monitoring via Equifax.
Johnson Controls reported a data breach to the Montana Attorney General. The breach was reported on 2025-06-30. The breach occurred from 02/01/2023 to 09/30/2023. 639 Montana residents were affected.
Affected (this filing): 639
Johnson Controls reported a data breach to the Indiana Attorney General. The breach occurred on 2023-02-01 and was reported on 2025-06-30. 16,729 Indiana residents were affected.
Affected (this filing): 16,729
Johnson Controls notified consumers of a cyber incident discovered in September 2023 involving unauthorized access to its network from February to September 2023. The incident resulted in the exfiltration of personal information, including names and credentials. Johnson Controls engaged third-party experts, terminated access, notified law enforcement, and offered two years of complimentary credit monitoring via Equifax.