Desk live·
ForensicPost
Ransomware/Manufacturing/File 23-0923

Johnson Controls Put Its Ransomware Response at $27 Million in an SEC Filing

A building automation company reported the cost of responding to a September attack, net of insurance recoveries. The operators claimed 27 terabytes and demanded $51 million — figures that exist only because the extortionists published them.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetJohnson Controls International
ActorDark Angels
S. Rosler10 min readConfidence: high2 sources reviewed

Johnson Controls International disclosed a cybersecurity incident in a Form 8-K filing and subsequently reported that expenses associated with responding to and remediating the attack were approximately $27 million, net of insurance recoveries, for the three months to 31 December 2023.

The company confirmed that data was stolen. Reporting attributed the attack to the operation tracked as Dark Angels.

Two Numbers, Two Origins

This file carries $27 million in the record and does not carry $51 million or 27 terabytes. The first is a figure a public company filed with a securities regulator and can be held to. The second and third are the extortionists’ own numbers, published to create pressure.

The corpus separates these routinely — at 24-1001, where a company notified 1.3 million people against an attacker claim of 2.9 billion records, and at 26-0215, where leaked chats showed demands priced off a commercial revenue database rather than off any valuation of the data.

Insurance Is Inside The Number

The $27 million is stated net of insurance recoveries, which makes it a figure about Johnson Controls’ own position rather than about the incident. The gross cost was higher and is not public.

The corpus files the general problem at 26-0416: cyber insurance is where a real cost figure goes to become a private one, and the most common ground for dispute is a control failure that contributed to the incident.

Building Systems Are An Operational Estate

Johnson Controls builds and services the systems that run heating, access control and fire safety in other organisations’ buildings. The corpus does not have evidence that customer building systems were affected here and does not assert it.

What it does record, at 26-0728 and 26-0311, is that the sector sits underneath other sectors, and that a supplier of operational technology is a different class of target from a supplier of software.

How we reported this

Built on Johnson Controls’ Form 8-K filings with the SEC and on contemporaneous reporting of the incident and the cost figure. The $27 million is the company’s reported expense net of insurance recoveries for a stated quarter, not a total cost of the incident. The $51 million demand and the 27-terabyte volume are the operators’ claims as reported, and appear in the body labelled as such; neither is in the record. The Dark Angels attribution is as reported and is not a finding of this desk. No claim is made about customer building systems. Graded high on the disclosure and the reported expense. Corrections: corrections@forensicpost.com.

Sources
  1. Johnson Controls International plc — Form 8-K, FY2023US Securities and Exchange Commission
  2. Johnson Controls says ransomware attack cost $27 million, data stolenBleepingComputer
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary