Foxconn has confirmed that some of its factories in North America have been by a cyberattack “ undertaken ” in recent days. Already, ransomware group Nitrogen has claimed responsibility, claiming to have stolen 8TB of data from the company . It is worth noting that Foxconn is one of Apple ’s main partners in manufacturing iPhones and other devices.

Nitrogen ransomware group targets Foxconn
The hacking group is said to be trying to blackmail Foxconn, claiming to have stolen data including blueprints and project details from clients including Dell, Google, Apple and Nvidia.
See also: Aviation targeted by ransomware gangs
This is not the first time Foxconn has been involved in a ransomware incident. In 2020, a Foxconn facility in Ciudad Juárez, Mexico, was hit by an attack that encrypted servers, stole data , and included a demand for bitcoin worth about $34.6 million at the time.
One of the plants affected in the new attack is the plant in Mount Pleasant (WI). The outage first became apparent on Friday, May 1, when employees at the Mount Pleasant campus reported a complete network outage.
By 7:00 a.m., the Wi-Fi had disappeared, and by 11:00 a.m., the outage had spread to key infrastructure at the factory. One worker reportedly said, “We were told to turn off our computers and not log in for any reason. The timecard terminals were dead. We were filling out paper timesheets just to track our hours.”
In addition to the Wisconsin, a Foxconn facility in Houston, Texas, also appears to have been affected.
See also: MuddyWater uses Chaos ransomware for “cover”

Apple doesn't seem to be affected
While Nitrogen has published a set of sample files allegedly stolen from Foxconn, there doesn't appear to be any Apple-related material. While it's not entirely certain, that's not particularly surprising given that Foxconn's Mount Pleasant facility primarily produces televisions and data servers , not Apple devices.
This attack is the latest in a series of cyberattacks and extortion attempts targeting Foxconn facilities in recent years. The company has faced several extortion, including a December 2020 attack on a facility in Mexico, where the DoppelPaymer ransomware group demanded 1,804 Bitcoin (worth about $34 million at the time).
The LockBit group hit another Foxconn facility in Mexico in May 2022 and disrupted production. More recently, LockBit attacked a subsidiary, called Foxsemicon Integrated Technology , with defacements and claims of a data breach.
Foxconn has not confirmed the extent of the incident but said the affected factories are "continuing production normally.".
See also: Latvian hacker convicted for participating in Ransomware campaign
The new cyberattack on Foxconn proves that even the largest industrial giants remain vulnerable to modern ransomware groups. With attacks now targeting critical supply chains and global technology suppliers, cybersecurity has become a key factor in business continuity. The fact that Nitrogen claims to have gained access to terabytes of corporate data and information from partners such as Apple, Google and Nvidia reinforces concerns about the impact such breaches can have on the entire technology industry ecosystem.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Meanwhile, the repeated targeting of Foxconn by ransomware groups highlights a broader trend: attackers are increasingly targeting industrial infrastructure and hardware manufacturers that must operate continuously. In manufacturing environments, even a few hours of downtime can cause huge financial losses, increasing pressure on companies to negotiate with the attackers. Although Foxconn maintains that production is continuing as normal, the incident highlights that cyberattacks are no longer just a technical problem, but a critical business and geopolitical issue for the global technology supply chain.
