2023 Johnson Controls — Dark Angels ransomware; multi-TB exfiltration claims; delayed consumer notices
Data compromised
Corporate and building-systems adjacent records described across law-firm summaries—field-level public mapping varies by notice cohort
Technical writeup
Johnson Controls International disclosed a September 2023 enterprise ransomware and data-exfiltration event attributed in security journalism to the Dark Angels group, with actors claiming tens of terabytes of archival theft, eight-figure ransom demands, and follow-on remediation costs above $27 million in vendor financial reporting. Late-2024 and 2025 coverage tracked long-cycle identity-notification programs as forensic scope matured.
Root cause
Ransomware deployment on internal IT with parallel bulk data theft (per vendor and BleepingComputer narratives)
References
- https://www.bleepingcomputer.com/news/security/johnson-controls-starts-notifying-people-affected-by-2023-breach/
- https://www.securityweek.com/johnson-controls-ransomware-attacks-data-theft-confirmed-cost-exceeds-27-million/
- https://www.cybersecuritydive.com/news/johnson-controls-ransomware-costs/706149/