{
  "type": "bundle",
  "id": "bundle--edeab3bc-3b1c-55a6-8633-b630e58ba05d",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--a04f2966-aaad-5d81-86aa-ed195b934fc0",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "org:1eabfb10-3baf-559d-9bcb-a2b6d5c87a18",
      "name": "Johnson Controls",
      "identity_class": "organization"
    },
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--524843f3-153b-5478-8ec9-a1a7e42cab5f",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "inc:d6fe61f8-d71c-514f-94b5-a7046fa923bf",
      "name": "Johnson Controls security incident"
    },
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--b61cd933-ebc7-5fba-80c8-89e9be1791ab",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "brh:f91203cd-60bb-5fe4-84b9-cad95683877c",
      "name": "Johnson Controls security incident"
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--65b0194c-3bd5-5325-893e-b55959bf489e",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "clm:e91382b1-fe1f-5d9d-a91c-e3a047c0bdf1",
      "relationship_type": "affected-organization",
      "source_ref": "incident--524843f3-153b-5478-8ec9-a1a7e42cab5f",
      "target_ref": "identity--a04f2966-aaad-5d81-86aa-ed195b934fc0",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "U.S. Securities and Exchange Commission",
          "url": "https://www.sec.gov/Archives/edgar/data/833444/000083344424000011/jci-20231231.htm",
          "external_id": "cit:4b675921-04f9-52f9-bdc7-34885fdffa09",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:9986a2e517ba3328d5195660e96b1ae02e3b71e9242c3d78ebf939c059a9fb65"
        }
      ]
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--2b564d6f-e983-5c96-81d9-3e6decb8175a",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:e8cfa180-4b35-5f63-9b94-e44064d461e5",
      "confidence": 90,
      "external_references": [
        {
          "source_name": "U.S. Securities and Exchange Commission",
          "url": "https://www.sec.gov/Archives/edgar/data/833444/000083344424000011/jci-20231231.htm",
          "external_id": "cit:9f41d21a-f08d-58f3-b2af-2562763c6db8",
          "description": "Based on the information reviewed to date, the Company believes the unauthorized activity has been contained and has not observed evidence of any impact to its digital products, services and solutions, including OpenBlue and Metasys.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:9986a2e517ba3328d5195660e96b1ae02e3b71e9242c3d78ebf939c059a9fb65"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "The retained source describes containment action intended to limit further access or disruption."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--556be5c0-a684-557b-84bf-7cf82d09c93b",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:4f83adfd-1bd1-53c1-af85-757b127eab0a",
      "confidence": 90,
      "external_references": [],
      "x_ally_claim_object": {
        "kind": "iri",
        "value": "https://attack.mitre.org/techniques/T1486/"
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--5a1b90f0-5a18-5521-8188-4d3d3fa359ad",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:641201b2-69a6-55b3-88f6-f400b6d22261",
      "confidence": 86,
      "external_references": [
        {
          "source_name": "U.S. Securities and Exchange Commission",
          "url": "https://www.sec.gov/Archives/edgar/data/833444/000083344424000011/jci-20231231.htm",
          "external_id": "cit:554ab739-0d59-59b8-9a8a-6a6bd9cd9aa0",
          "description": "The cybersecurity incident consisted of unauthorized access, data exfiltration and deployment of ransomware by a third party to a portion of the Company’s internal IT infrastructure.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:9986a2e517ba3328d5195660e96b1ae02e3b71e9242c3d78ebf939c059a9fb65"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "Dark Angels ransomware."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--c929d275-bf17-5a2d-8135-3aea0b81bc2c",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "clm:0bfeb023-75ee-51fd-8994-19e2e5f52f82",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "U.S. Securities and Exchange Commission",
          "url": "https://www.sec.gov/Archives/edgar/data/833444/000083344424000011/jci-20231231.htm",
          "external_id": "cit:7ad71b1b-f0a7-5ab7-be07-03cffb7871fa",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:9986a2e517ba3328d5195660e96b1ae02e3b71e9242c3d78ebf939c059a9fb65"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "The reviewed source documents the johnson controls security incident involving Johnson Controls."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--dbc8f484-1074-5b39-899c-1941ec381926",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:e09fc427-129a-5505-84d9-fdc9fe34ca0d",
      "confidence": 90,
      "external_references": [
        {
          "source_name": "U.S. Securities and Exchange Commission",
          "url": "https://www.sec.gov/Archives/edgar/data/833444/000083344424000011/jci-20231231.htm",
          "external_id": "cit:f1dc4c59-7cae-5854-9b36-442720e5b0c5",
          "description": "The Company also engaged leading cybersecurity experts and other specialized consultants to assist in its investigation and remediation of the incident, as well as the restoration of impacted applications and systems.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:9986a2e517ba3328d5195660e96b1ae02e3b71e9242c3d78ebf939c059a9fb65"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "The retained source describes system restoration or operational recovery work."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--e2e0eacd-c3a4-5e22-868f-952aa2dcb0a0",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:4420d544-712e-590b-aa3a-31d43b260fce",
      "confidence": 90,
      "external_references": [
        {
          "source_name": "U.S. Securities and Exchange Commission",
          "url": "https://www.sec.gov/Archives/edgar/data/833444/000083344424000011/jci-20231231.htm",
          "external_id": "cit:37132686-6c76-5247-9774-84369d1b094e",
          "description": "The Company also engaged leading cybersecurity experts and other specialized consultants to assist in its investigation and remediation of the incident, as well as the restoration of impacted applications and systems.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:9986a2e517ba3328d5195660e96b1ae02e3b71e9242c3d78ebf939c059a9fb65"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "The retained source describes a forensic or specialist investigation of the incident."
      }
    }
  ]
}
