ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Johnson Matthey faces third-party data breach, exposing employee records

Johnson Matthey, a leading sustainable technology company based in London, has disclosed a significant third-party data breach, compromising over 6000 employee records. The breach, attributed to human error, underscores the challenges companies face in safeguarding sensitive information in an increasingly interconnected digital landscape. 

 

In a letter released on March 18th, the British multinational chemical company acknowledged the breach, emphasizing its commitment to protecting employees’ personal information despite the cybersecurity incident. The compromised data included "employment-related documents" containing sensitive details such as names, Social Security numbers, and dates of birth. 

 

The breach was discovered on February 15th, 2024, when Johnson Matthey identified files containing personal information of US employees stored on a third-party platform. The company, seemingly unaware of the data’s presence on the external system, promptly retrieved and removed the files upon discovery, initiating a thorough investigation into the incident. 

 

According to the breach notification letter, the files were inadvertently uploaded to the storage platform by a contractor hired by the company. These files, believed to have been stored on the platform since 2020 without proper access controls, remained accessible to potential adversaries due to the lack of security measures. 

 

Despite the breach spanning four years, Johnson Matthey has not found evidence suggesting unauthorized access or download of the data. Nevertheless, the absence of access controls on the external platform raises concerns about the potential vulnerability of the exposed information. 

 

In response to the breach, Johnson Matthey has taken proactive measures, conducting searches across external platforms to prevent further dissemination of compromised data. Additionally, the company has announced compensation in two years of identity protection services for affected employees, aiming to mitigate potential identity theft or fraud risks. 


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543