Johnson Controls International was the victim of a ransomware (Dark Angels) that resulted in the encryption of many of the company's devices, including VMware ESXi servers. The attack affected the operations of both the company and its subsidiaries.
Johnson Controls is a multinational group that develops and manufactures industrial control systems, safety, air conditioning and fire protection equipment. It employs 100,000 people through its corporate operations and subsidiaries, including York, Tyco, Luxaire, Coleman, Ruskin, Grinnel and Simplex.

Ransomware attack
According to BleepingComputer, Johnson Controls has been hit by a ransomware attack, initially targeting its offices in Asia. The attack took place over the weekend and forced the company to shut down parts of its IT systems.
Since then, many of its subsidiaries, including York, Simplex and Ruskin, have begun displaying messages on website login pages and customer portals, citing technical outages.
“We are currently experiencing an IT outage that may limit some customer applications, such as the Simplex Customer Portal,” a message on the Simplex website states.
“We are mitigating potential impacts to our services and will remain in communication with customers as these outages are resolved“.
Customers of York, another Johnson Controls subsidiary, say the company told them there were problems due to a cyberattack.
" Their system crashed over the weekend. Production and everything is down ," one York customer wrote on Reddit
"I spoke to our representative and he said someone hacked them," another customer posted.
Nextron Systems threat researcher Gameel Aliposted on Twitter a sample of the Dark Angels ransomware gang's VMware ESXi encryptor, which contained a ransom against Johnson Controls.
BleepingComputer reports that the ransom note is linked to a negotiation attempt between the hacker and the company. The ransomware gang is reportedly demanding $51 million to provide a decryption tool and delete the data it stole from Johnson Controls.
The hackers claim to have stolen over 27 TB of corporate data and encrypted the company's VMWare ESXi virtual machines.
Johnson Controls confirmed the ransomware attack in an 8-K filing with the SEC. An excerpt from the filing:
“Johnson Controls International plc (the “Company”) has experienced disruptions to parts of its internal IT infrastructure and applications as a result of a cybersecurity. Immediately after the issue was identified, the Company initiated an investigation with the assistance of leading external cybersecurity experts and is also working with its insurers. The Company continues to assess what information was impacted and is executing its incident management and protection plan, including implementing remediation measures to mitigate the impact of the incident. The Company will continue to take additional measures as appropriate. To date, many of the Company’s applications remain largely unaffected and operational. To the extent possible and in accordance with its business continuity plans, the Company has implemented workarounds for certain functions to mitigate disruptions and continue to serve its customers. However, the incident has caused and is expected to continue to cause disruptions to parts of its business operations. The Company is assessing whether the incident will affect its ability to timely publish its fourth quarter and full fiscal year results, while also assessing the impact on its financial results.
The Company's investigation and recovery efforts continue“.

Dark Angels ransomware
Dark Angels is a ransomware operation that was detected in May 2022 when it began targeting organizations around the world.
The Dark Angels breach corporate networks and then spread and steal data to use for double blackmail.
They then deploy ransomware to encrypt all devices on the network.
Initially, they used Windows and VMware ESXi encryptors based on the source code for the Babuk ransomware.
However, MalwareHunterTeam told BleepingComputer that the Linux encryptor used in the Johnson Controls attack is the same one used by Ragnar Locker since 2021.
Dark Angels created a data leak website in April 2023 called “Dunghill Leaks.” This website already has nine victims, including Sabre and Sysco, which recently disclosed cyberattacks.
Ransomware attacks have immediate and serious consequences for companies. These attacks are usually followed by a recovery period, during which the company must get its systems and applications back up and running as quickly as possible. This process can be laborious and time-consuming, especially if the company’s data has been encrypted or, worse, stolen. If the company decides to pay the ransom , the financial burden can be significant. However, paying does not always guarantee that the systems will be restored or the data will be returned . Finally, customer trust and the company’s reputation can be significantly damaged, and it can take a long time to recover.
Source: www.bleepingcomputer.com
