{"id":1803,"date":"2023-09-29T18:41:00","date_gmt":"2023-09-29T18:41:00","guid":{"rendered":"https:\/\/www.darkreading.com\/ics-ot\/dhs-physical-security-concern-johnson-controls-cyberattack"},"modified":"2023-09-29T18:41:00","modified_gmt":"2023-09-29T18:41:00","slug":"dhs-physical-security-a-concern-in-johnson-controls-cyberattack","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2023\/09\/29\/dhs-physical-security-a-concern-in-johnson-controls-cyberattack\/","title":{"rendered":"DHS: Physical Security a Concern in Johnson Controls Cyberattack"},"content":{"rendered":"<p><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/dhs-physical-security-a-concern-in-johnson-controls-cyberattack.jpg?w=640&#038;ssl=1\"><\/p>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/dhs-physical-security-a-concern-in-johnson-controls-cyberattack-1.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<div readability=\"47.892200695479\">\n<div readability=\"46.549428713363\">\n<p>In the latest development around the&nbsp;<a href=\"https:\/\/www.darkreading.com\/ics-ot\/johnson-controls-international-hit-with-massive-ransomware-attack\">cyberattack impacting Johnson Controls International (JIC)<\/a>, officials at the Department of Homeland Security (DHS) are now reportedly concerned that the attack may have affected sensitive physical security information.<\/p>\n<p>Johnson Controls serves as a government contractor, providing building automation services to facilities,&nbsp;such as HVAC, fire, and security equipment. Due to the nature of those services, officials at DHS are raising concerns about compromised information such as DHS floor plans. According to<a href=\"https:\/\/www.cnn.com\/2023\/09\/28\/politics\/dhs-investigating-ransomware-attack\/index.html\" target=\"_blank\" rel=\"noopener\">&nbsp;media reports, officials detailed in an internal memo<\/a>&nbsp;that Johnson Controls holds&nbsp;&#8220;classified\/sensitive contracts for DHS that depict the physical security of many DHS facilities.&#8221;<\/p>\n<p><span>It is still unclear as to what information was accessed in the breach, which is believed to be a ransomware attack, but the memo stated that &#8220;until further notice, we should assume that [the contractor] stores DHS floor plans and security information tied to contracts on their servers.&#8221;<\/span><\/p>\n<p>Concerns are more heightened due to <a href=\"https:\/\/www.darkreading.com\/cloud\/government-shutdown-poised-to-stress-nation-s-cybersecurity-supply-chain\" target=\"_blank\" rel=\"noopener\">a potential government shutdown<\/a>, which could begin this coming Sunday, making the incident not only a security issue, but a time sensitive one. More than 80% of the Cybersecurity and Infrastructure Security Agency (CISA) workforce will be furloughed should this shutdown go into effect, and cyberattacks across the nation&#8217;s software supply chain would&nbsp;put critical infrastructure at risk.<\/p>\n<p>&#8220;There is absolutely a trend emerging in ransomware attacks with cybercriminals going deeper into their victims&#8217; systems to deal a more crippling blow,&#8221; noted John Gunn, CEO at&nbsp;Token, in an emailed statement, underscoring the harsh levels cybercriminals are willing to go to in their attacks, including those against government agencies.<\/p>\n<p>This incident highlights the&nbsp;<a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/white-house-orders-federal-agencies-to-bolster-cyber-safeguards\">executive order President Biden issued in 2021<\/a>&nbsp;for federal agencies to bolster their cybersecurity safeguards, and brings into question the security of&nbsp;<a href=\"https:\/\/www.darkreading.com\/endpoint\/greater-manchester-police-hack-third-party-supplier-fumble\">third-party suppliers<\/a>&nbsp;and contractors.&nbsp;<\/p>\n<\/div>\n<\/div>\n<div id=\"articleFooter-newsletterSignup\" readability=\"10.473404255319\">\n<p>Keep up with the latest cybersecurity threats, newly-discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.<\/p>\n<p><a class=\"subscribe-btn dr-btn\" href=\"https:\/\/darkreading.tradepub.com\/c\/pubRD.mpl?secure=1&amp;sr=pp&amp;_t=pp:&amp;qf=w_defa3135&amp;ch=dr_eoa\" title=\"Subscribe\" target=\"_blank\" rel=\"noreferrer noopener\">Subscribe<\/a><\/div>\n<p><a href=\"https:\/\/www.darkreading.com\/ics-ot\/dhs-physical-security-concern-johnson-controls-cyberattack\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In the latest development around the&nbsp;cyberattack impacting Johnson Controls International<\/p>\n","protected":false},"author":12,"featured_media":1804,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-1803","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/dhs-physical-security-a-concern-in-johnson-controls-cyberattack.jpg?fit=342%2C343&ssl=1",342,343,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/dhs-physical-security-a-concern-in-johnson-controls-cyberattack.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/dhs-physical-security-a-concern-in-johnson-controls-cyberattack.jpg?fit=300%2C300&ssl=1",300,300,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/dhs-physical-security-a-concern-in-johnson-controls-cyberattack.jpg?fit=342%2C343&ssl=1",342,343,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/dhs-physical-security-a-concern-in-johnson-controls-cyberattack.jpg?fit=342%2C343&ssl=1",342,343,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/dhs-physical-security-a-concern-in-johnson-controls-cyberattack.jpg?fit=342%2C343&ssl=1",342,343,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/dhs-physical-security-a-concern-in-johnson-controls-cyberattack.jpg?fit=342%2C343&ssl=1",342,343,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/dhs-physical-security-a-concern-in-johnson-controls-cyberattack.jpg?fit=342%2C343&ssl=1",342,343,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/dhs-physical-security-a-concern-in-johnson-controls-cyberattack.jpg?resize=342%2C343&ssl=1",342,343,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/dhs-physical-security-a-concern-in-johnson-controls-cyberattack.jpg?resize=342%2C343&ssl=1",342,343,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/dhs-physical-security-a-concern-in-johnson-controls-cyberattack.jpg?fit=342%2C343&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/1803","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=1803"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/1803\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/1804"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=1803"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=1803"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=1803"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}