Johnson Controls Data Breach Notice (Oregon Attorney General)
If you received a notice from Johnson Controls, here’s what the filing says was exposed, and what to do about it.
Johnson Controls notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on July 01, 2025. The filing puts the incident itself on February 01, 2023.
The February 01, 2023 breach at Johnson Controls exposed personal information belonging to 3,829 people. The organisation did not file its notification with the Oregon Attorney General until July 01, 2025 — an interval of 881 days, or nearly 29 months.
Personal information that cannot be replaced
The filing lists personal information as the category exposed in the incident. No passwords, no financial account numbers, and no government identifiers such as Social Security numbers appear in the disclosed categories. That absence is meaningful: nothing in this breach gives an attacker the ability to take over an existing account at Johnson Controls or any linked financial service.
What was lost is the permanent biographical core that identity thieves rely on for years. Names, addresses, dates of birth and similar details do not expire. Once they leave an organisation’s control they remain valuable for fraud, account takeover attempts, and synthetic identity schemes long after the initial headlines fade.
What the long notification delay changes for you
A gap of almost three years between the incident and the formal filing is the single most striking fact in the record. During that period the organisation conducted whatever investigation it deemed necessary before notifying affected Oregon residents. The filing itself offers no explanation of the cause, the method of access, or whether data left the company’s environment immediately or later.
Because the record is silent on those details, the practical reality is simple: personal information that was inside Johnson Controls on February 01, 2023 is now presumed to be outside its control. You cannot change the facts of that date, but you can decide how much weight you give them going forward.
How to determine whether this notice applies to you
Johnson Controls is required to notify affected individuals directly, usually by mail to the last known address on file. If you have not received a letter, it is likely your records were not part of the 3,829 affected. However, anyone who has moved since February 01, 2023 should contact the organisation directly to confirm whether their information was included.
The lasting value of the exposed data
Personal information of this kind retains utility for identity thieves far longer than a credit card number. A date of birth combined with a name and prior address becomes a building block for impersonation attempts, loan applications in your name, or tax fraud. These records do not lose relevance after a few months; they become part of the permanent background data available to determined fraudsters.
The absence of passwords and account credentials in the exposed categories is genuinely good news. There is no need to change any Johnson Controls password because of this incident, and no evidence that login credentials were compromised. That removes one major category of immediate risk that often accompanies breaches.
What remains under your control
While you cannot rewrite the past, several practical steps still matter. Monitoring for new account fraud, placing alerts with the credit bureaus, and being vigilant about unexpected tax documents or benefit statements are the actions that address the specific exposure here. The exposed personal information raises the long-term probability of targeted fraud attempts rather than an immediate account takeover.
The record establishes only what was exposed and to how many Oregon residents. It does not describe the root cause, the duration of any unauthorised access, or the organisation’s internal security measures. Those details remain outside the filing and therefore outside what can be stated with certainty.
For most people the letter in the mail remains the clearest signal. If it arrived, treat the personal information listed in it as public. If it never arrived and you have lived at the same address since early 2023, the odds are strongly in your favour that you were not included. When in doubt, a direct inquiry to Johnson Controls is the only way to close the question the filing leaves open.
Report details & sourcing
Related breaches
Livara Health Medical Group Data Breach Notice (California Attorney General)
Livara Health Medical Group notified California residents of a data breach in a filing reported to t…
Pan American Group LLC Data Breach Notice (California Attorney General)
Pan American Group LLC notified California residents of a data breach in a filing reported to the Ca…
Punch & Associates Investment Management, Inc. Data Breach Notice (Vermont Attorney General)
Punch & Associates Investment Management, Inc. notified Vermont residents of a data breach in a fili…