Johnson Controls Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do
Johnson Controls disclosed a data breach on July 01, 2025, that exposed the personal information of 3,829 individuals; the intrusion occurred on or around February 01, 2023. If you have any connection to Johnson Controls, review the Oregon Attorney General notice and take steps to protect your information.
Organizations that design and manage the systems inside commercial buildings, factories, and critical facilities remain frequent targets in a threat landscape where stolen personal data is routinely monetized and reused for fraud. Against that backdrop, a delayed public notice has brought a multi-year-old incident at Johnson Controls into clearer view for residents who may have been affected.
Johnson Controls notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on July 1, 2025. The filing places the incident itself on February 1, 2023, and states that 3,829 people were affected. The notice describes the exposed material as personal information. Exact technical details of how the intrusion occurred have not been publicly elaborated in the available disclosure.
What happened
According to the breach notice filed with the Oregon Attorney General’s office, Johnson Controls experienced a data incident dated February 1, 2023. The company later submitted formal notification to Oregon authorities, with that filing recorded on July 1, 2025. The notice identifies 3,829 affected individuals and characterizes the exposed data as personal information.
Public detail beyond those points is limited. The filing does not, in the information provided here, describe the intrusion method, the duration of unauthorized access, whether data was exfiltrated in bulk or selectively, or whether any ransom demand or leak-site posting accompanied the event. No specific threat actor is named in the disclosure. The gap between the stated incident date and the Oregon filing date is noted in the record but not explained further in the available summary.
How a breach like this happens
Incidents that later surface as “personal information” notices commonly begin with one of several well-understood paths. Attackers may obtain valid credentials through phishing, password reuse, or commodity stealer malware, then move laterally inside corporate networks. Alternatively, unpatched remote-access services, misconfigured cloud storage, or compromised third-party vendors can provide an initial foothold. Once inside, the goal is often to locate directories or file shares that contain employee, customer, or partner records.
In many cases the organization discovers the activity weeks or months later through internal monitoring, law-enforcement notification, or external reporting. Forensic work then determines which systems and data sets were touched. Notification timelines are governed by state law; Oregon and other jurisdictions require notice to residents and to the attorney general once the scope of personal information involved is reasonably established. Because no threat group is attributed in this filing, it is not possible to tie the event to any particular known campaign or tooling set.
Johnson Controls and its sector
Johnson Controls is a large industrial and technology company whose products and services center on building systems—heating, ventilation, air conditioning, fire protection, security, and related controls and software. Its customers include commercial real estate, manufacturing sites, healthcare facilities, educational institutions, and other operators of complex physical infrastructure. Companies in this sector typically maintain substantial volumes of business contact data, employee records, contractor information, and sometimes operational or facility-related details needed to deliver and support those systems.
A breach affecting such an organization matters because the same personal data that supports contracts, service calls, and employment can be reused by criminals for identity fraud, business-email compromise, or further social-engineering attacks against the company’s clients and partners. Even when the core industrial-control or building-management systems themselves are not reported as compromised, the administrative and customer-facing data stores remain attractive targets.
The information in question
The Oregon notice states that personal information was exposed. It does not itemize the precise data elements—such as names, addresses, dates of birth, Social Security numbers, driver’s-license numbers, financial account details, or health-related identifiers—in the summary available here. Public detail on the exact fields is therefore limited.
Organizations of this type commonly hold employee and contractor personnel files, customer and prospect contact records, billing and payment information, and authentication credentials used for service portals. Any combination of those categories can fall under the broad label “personal information” in a state breach notice. Because the filing does not confirm which specific elements were involved, readers should treat the contents as unconfirmed beyond the general category already disclosed.
The real-world impact
For the 3,829 people identified in the Oregon filing, the practical risk is the ordinary but persistent set of harms that follow exposure of personal information: account takeover attempts, fraudulent credit or loan applications, targeted phishing that references real personal details, and the time cost of monitoring and correcting errors on credit reports. The multi-year interval between the stated incident date and the 2025 notification means some individuals may already have experienced unexplained activity without connecting it to this event.
For Johnson Controls, the consequences include regulatory notification obligations, potential credit-monitoring or identity-protection offers required or expected under state law, internal investigation and remediation costs, and reputational questions from customers who rely on the company for building safety and operational technology. No dollar figures, litigation outcomes, or confirmed secondary fraud cases are stated in the facts provided.
What to do if you're exposed
If you believe you may be among those notified, begin by reading any letter or email you received from Johnson Controls carefully and retaining it. Place a fraud alert or credit freeze with the major credit bureaus if you have not already done so, and review your credit reports and financial statements for unfamiliar accounts or inquiries. Change passwords on any accounts that reused credentials associated with the company, and enable multi-factor authentication wherever it is offered. Be skeptical of unexpected calls or messages that reference the breach and ask for additional personal data or payment.
You can also run a free exposure scan of your email address to check whether that address or related credentials have already appeared in other known breach data sets; doing so gives a broader picture of your existing exposure beyond this single incident. If you receive a formal notice, follow the specific instructions and any enrollment windows it provides for credit monitoring or identity-protection services. Keep records of all correspondence in case you later need to dispute fraudulent activity.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Decisely Insurance Services Data Breach Notice (Oregon Attorney General)Apro, LLC d/b/a United Pacific Data Breach Notice (Oregon Attorney General)Apro, LLC d/ Data Breach Notice (Oregon Attorney General)CareOregon Data Breach Notice (Oregon Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.