• News/
  • https://www.bleepingcomputer.com/news/security/johnson-controls-starts-notifying-people-affected-by-2023-breach/

Johnson Controls starts notifying people affected by 2023 breach

BleepingComputer
·
Sergiu Gatlan
·
Published Jul 1, 2025
·
Updated

Building automation giant Johnson Controls is notifying individuals whose data was stolen in a massive ransomware attack that impacted the company's operations worldwide in September 2023. Johnson Controls is a multinational conglomerate that develops and manufactures industrial control systems, security equipment, HVAC systems, and fire safety equipment for buildings. The company employs over 100,000 people through its corporate operations and subsidiaries across 150 countries, reporting sales of $27.4 billion in 2024. As BleepingComputer first reported, Johnson Controls was hit by a ransomware attack in September 2023, following a breach of the company's Asian offices in February 2023 and subsequent lateral movement through its network. "Based on our investigation, we determined that an unauthorized actor accessed certain Johnson Controls systems from February 1, 2023 to September 30, 2023 and took information from those systems," the company says in data breach notification letters filed with California's Attorney General, redacted to conceal what information was stolen in the attack. "After becoming aware of the incident, we terminated the unauthorized actor's access to the affected systems. In addition, we engaged third-party cybersecurity specialists to further investigate and resolve the incident. We also notified law enforcement and publicly disclosed the incident in filings on September 27, 2023; November 13, 2023; and December 14, 2023." The cyberattack forced John...

Read full article

Affected Software

4 affected components
Johnson Controls industrial control systems
Johnson Controls security equipment
Johnson Controls HVAC systems
Johnson Controls fire safety equipment

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Johnson Controls notifying individuals affected by a data breach resulting from a ransomware attack in September 2023.

2

What security implications are discussed in the article?

The article highlights the risks associated with ransomware attacks and the potential exposure of personal data due to inadequate security measures.

3

What specific products or systems are affected by the breach?

The breach affects various Johnson Controls products, including industrial control systems, security equipment, HVAC systems, and fire safety equipment.

4

When did the ransomware attack on Johnson Controls occur?

The ransomware attack that impacted Johnson Controls' operations occurred in September 2023.

5

How is Johnson Controls responding to the data breach?

Johnson Controls is actively notifying individuals whose data was compromised as part of their response to the breach.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203