ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Johnson Controls data breach possibly compromised US Department of Homeland Security's classified data

A recent cyber attack on Johnson Controls, a leading manufacturer of industrial control systems, reportedly compromised sensitive information belonging to the US Department of Homeland Security.In September, several subsidiaries of Johnson Controls International, including York, Tyco, Luxaire, Coleman, Ruskin, Grinnel, and Simplex confirmed that their parent company suffered “IT outages” that affected several internal systems, including those of its subsidiaries.“We are currently experiencing IT outages that may limit some customer applications such as the Simplex Customer Portal. We are actively mitigating any potential impacts to our services and will remain in communication with customers as these outages are resolved,” reads a notice posted on the Simplex website.In a 8-K filing with the US Securities and Exchange Commission, the industrial control systems manufacturer acknowledged that it had indeed suffered a cyber attack, stating that it was working with external cyber security experts to investigate the incident on priority.Malware repository VX-Underground confirmed on X, formerly Twitter, that a group of threat actors going by the name Dark Angels claimed responsibility for the cyber attack on Johnson Controls by listing the company on its data leak site.The group claims to be in possession of 27 terabytes of sensitive data stolen from Johnson Controls. According to BleepingComputer, the ransomware group encrypted the company’s VMWare ESXi virtual machines during the attack and demanded a ransom of $51 million in exchange for a decryption key and deletion of the stolen data.Recently, CNN reported that an internal Department of Homeland Security correspondence, that it was able to access, revealed that senior DHS officials are investigating whether the ransomware attack on Johnson Controls compromised any sensitive confidential data belonging to the department.According to the internal communication, Johnson Controls is in possession of “classified/sensitive contracts for DHS that depict the physical security of many DHS facilities”.“Until further notice, we should assume that [the contractor] stores DHS floor plans and security information tied to contracts on their servers. We do not currently know the full extent of the impact on DHS systems or facilities,” the internal communication reads.In its regulatory filing, the Johnson Controls said, “The Company continues to assess what information was impacted and is executing its incident management and protection plan, including implementing remediation measures to mitigate the impact of the incident, and will continue taking additional steps as appropriate.“To date, many of the Company’s applications are largely unaffected and remain operational. To the extent possible, and in line with its business continuity plans, the Company implemented workarounds for certain operations to mitigate disruptions and continue servicing its customers.“The Company’s investigation and remediation efforts are ongoing,” it added.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543