Foxconn Confirms Ransomware Attack on North American Factories

The attack exposed how a single supplier breach can create cascading risk across the global technology supply chain.

Illustration: Foxconn Confirms Ransomware Attack on North American Factories
AI-generated illustration · Sylvaris

What happened

Foxconn, the world's largest contract electronics manufacturer, confirmed on May 12 that several of its North American factories suffered a cyberattack. The Nitrogen ransomware group had claimed responsibility one day earlier, posting details to its dark web leak site.

The group asserted it had stolen eight terabytes of data comprising more than 11 million files. Those files allegedly included confidential project documentation, technical drawings, and schematics tied to major Foxconn clients including Apple, Nvidia, Intel, Google, and Dell.

How production was affected

Before Foxconn confirmed the attack publicly, employees at its Mount Pleasant, Wisconsin facility reported being sent home after widespread network and Wi-Fi outages disrupted operations. The company stated that its cybersecurity team activated response measures to ensure continuity, and that affected factories were resuming normal production.

Foxconn manufactures components and devices for many of the world's largest technology companies. The incident follows a pattern of repeated ransomware targeting against the company, with previous attacks by DoppelPaymer in 2020 and LockBit in 2022 and 2024.

The supply chain dimension

The breach demonstrates how a single supplier can become a concentration risk across the entire hardware industry. Foxconn reported $258.3 billion in revenue in 2025 and employs more than 900,000 people across facilities in 24 countries. If the claims about stolen technical documentation are accurate, the information could be used for industrial espionage, vulnerability discovery, or supply-chain compromise.

Security researchers noted that earlier in 2026, a programming error was discovered in Nitrogen's decryption tool that prevents recovery of files on VMware ESXi systems, meaning that paying the ransom may not guarantee data recovery.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.