Quick Facts
- Foxconn confirmed a cyberattack hit its North American facilities, with hackers claiming to steal 8TB of data including 11 million files
- The Nitrogen ransomware group says it obtained technical drawings and project documentation for Intel, Apple, Google, Dell, and Nvidia
- Affected factories are resuming normal production after network outages forced some workers to use manual processes
Electronics manufacturing giant Foxconn confirmed Monday that hackers breached its North American facilities in a cyberattack that disrupted operations for nearly two weeks.
The Nitrogen ransomware group claimed responsibility for the attack, asserting it stole 8 terabytes of data containing more than 11 million files. The hackers say the stolen information includes confidential instructions, internal project documentation, and technical drawings related to projects at Intel, Apple, Google, Dell, and Nvidia.
“Some of Foxconn’s factories in North America suffered a cyberattack,” a Foxconn spokesperson told The Register. “The cybersecurity team immediately activated the response mechanism and implemented multiple operational measures to ensure the continuity of production and delivery.”
The attack primarily affected Foxconn facilities in Mount Pleasant, Wisconsin, and Houston, Texas. Workers reported a complete network collapse on May 1, with Wi-Fi systems failing by 7 AM and disruption spreading through core plant infrastructure by 11 AM.
“We were told to turn off our computers and not log back in under any circumstances,” said one worker who requested anonymity. “The timecard terminals were dead.”
The outage forced some staff to use manual paper-based processes while systems were restored. Some workers were sent home during parts of the disruption, though Foxconn said production operations were not permanently halted.
Security experts warn the breach could have broader implications beyond Foxconn. “The real concern is that Google and Intel’s network topologies have been stolen,” said security analyst Mark Henderson. “Because this is an architectural map of operational infrastructure, attackers could use this data to identify vulnerabilities in data centers around the world.”
Based on sample files, the stolen data does not appear to include Apple schematics or product development documentation. Foxconn’s Mount Pleasant facility primarily produces televisions and data servers rather than Apple devices.
This marks at least the third major ransomware attack against Foxconn. The company faced previous incidents in December 2020, May 2022, and 2024, highlighting persistent security vulnerabilities in global electronics supply chains.
Nitrogen has operated since 2023 and uses double-extortion tactics, both encrypting files and threatening to leak stolen data. In February, researchers warned that programming errors in the group’s decryption tools may prevent file recovery even if victims pay ransom demands.
Foxconn, which employs more than 900,000 workers across 240 facilities in 24 countries and reported revenues exceeding $260 billion last year, declined to confirm whether customer information was compromised or whether it received ransom demands.
This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.
