Incident · 8-K Item 8.01
Johnson Controls reports disruption to internal IT infrastructure from a cybersecurity incident
Compiled 2026-09-27 from public records. By the cisonews.net Desk.
Johnson Controls International, the building systems and HVAC company, disclosed on September 27, 2023 that a cybersecurity incident had disrupted portions of its internal information technology infrastructure and applications. It was also weighing whether the incident would delay its fiscal year-end results.
What Johnson Controls said
The company said many applications were largely unaffected and that it had put workarounds in place for some operations. It was still assessing what information was involved.
The filing raised a reporting question that few others in this log mention.
What is missing
Johnson Controls gave no detection date, did not describe the attack, and made no materiality finding in this filing. It said it was coordinating with insurers. No follow-up 8-K for the incident is in this log, so the eventual cost and any data findings are not recorded on this page.
Sources
- 2023-09-27 · AJohnson Controls International plc, Form 8-K (SEC EDGAR), published September 27, 2023
Tier A: the organization itself, a regulator or SEC EDGAR. Tier B: established press. Each fact on this page carries its supporting passage in the page source.
See an error? Corrections are made on the page and logged on the corrections page. Send them through contact.