Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Johnson Controls detected outages during the weekend of September 23, 2023, and later disclosed that a third party had gained unauthorized access to part of its internal IT infrastructure and deployed ransomware. The incident disrupted business applications and delayed fiscal year-end reporting. In a later filing, the company said the affected systems had been restored and reported an approximately $27 million net-income impact for the quarter ended December 31, 2023, after insurance recoveries. The company filings do not confirm what specific data was taken or validate a ransomware group’s claim that it stole 27 TB.

What happened in the Johnson Controls ransomware attack?

Johnson Controls International plc said it detected the incident after experiencing outages during the weekend of September 23, 2023. In a November 13, 2023 filing with the U.S. Securities and Exchange Commission, the company described unauthorized access and third-party ransomware deployment affecting a portion of its internal IT infrastructure. It said parts of its business applications, supporting operations, and corporate functions were disrupted or had limited access. The company’s November 2023 Form 8-K also said it activated incident-management and business-continuity plans and engaged cybersecurity experts and specialized consultants.

In its subsequent quarterly filing, Johnson Controls described the incident as involving unauthorized access, data exfiltration, and ransomware. Disruption continued into the early part of fiscal first-quarter 2024. The company said the affected applications and systems had been restored by the filing date, and that its investigation included analysis of data accessed, exfiltrated, or otherwise affected. The Form 10-Q for the quarter ended December 31, 2023 provides that later account.

What systems and services were affected?

The company disclosed disruption to parts of its internal IT environment and the business applications that support operations and corporate functions. That disruption also affected financial reporting processes. Johnson Controls said it had not observed evidence of an impact to its digital products, services, and solutions, including OpenBlue and Metasys, based on information reviewed at the time of its filings.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That statement is the company’s account at those points in time. It is not independent confirmation about every customer system or a guarantee that no customer environment was affected. The company’s current cybersecurity response page gives general guidance on topics such as vulnerability reporting and hardening; it is not a description of the 2023 incident.

How did the attack affect reporting and finances?

Delayed fiscal 2023 reporting

Disruption to systems supporting financial reporting delayed Johnson Controls’ fiscal 2023 fourth-quarter and year-end reporting process. In its November 2023 filing, the company said related data had been reconciled and verified and that it expected to report by December 14, 2023. That was the expectation stated in that filing, not a current forecast.

Reported impact for the quarter ended December 31, 2023

Johnson Controls reported an approximately $27 million net-income impact for the three months ended December 31, 2023, from lost and deferred revenues and incident expenses, net of insurance recoveries. The company said the impact was primarily attributable to response and remediation expenses. It also said disruption to its billing system negatively affected cash provided from operations during that quarter.

Costs and insurance expectations

In its quarterly filing, the company expected additional response and remediation expenses through fiscal 2024, with most expected in the first half. It also expected insurance to reimburse a substantial portion of direct costs and business-interruption losses. Those were expectations disclosed at the time; they are not a final realized total for the incident.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What data did the attackers steal?

The cited company filings do not identify the specific contents of data exfiltrated or confirm a volume. SecurityWeek reported in September 2023 that the ransomware group claimed to have stolen 27 TB, but that figure is a threat-actor claim, not a company-confirmed breach volume. SecurityWeek’s contemporaneous report should be read with that distinction in mind.

Cybersecurity Dive quoted Allan Liska, a threat intelligence analyst at Recorded Future, saying at the time: “However, we still don’t know what was in the data stolen by the ransomware group.” That comment described the uncertainty then; it is not a later finding by Johnson Controls. Cybersecurity Dive’s report covered the incident as it was unfolding.

What is confirmed—and what is not?

  • Confirmed by Johnson Controls: It detected outages during the weekend of September 23, 2023, and described unauthorized access and ransomware affecting part of its internal IT infrastructure.
  • Confirmed by Johnson Controls: Business applications and supporting operations and corporate functions were disrupted, with effects continuing into early fiscal Q1 2024; the company later said the affected systems had been restored.
  • Confirmed as a reported financial impact: The company reported approximately $27 million of net-income impact for the quarter ended December 31, 2023, net of insurance recoveries.
  • Not established by the cited filings: The specific data taken, its categories, or the amount actually exfiltrated.
  • Not independently verified in the company filings: The ransomware group’s claim that it stole 27 TB.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.