CSIDB logo
Incident

Hon Hai Precision Industry Co., Ltd.

Incident posture

Attack window
May 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-10 13:34

Linked entities

Victim
Hon Hai Precision Industry Co., Ltd.
Threat actors
1 actor
Sources
7 sources

Timeline

Occurred
May 2026
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Hon Hai Precision Industry Co., Ltd. (Foxconn) experienced a cyberattack claimed by the ransomware group Nitrogen, which asserted theft of approximately eight terabytes of data comprising around eleven million files, including schematics from major technology partners. The attack affected some of the company's North American facilities, prompting operational measures to restore normal operations while investigators assessed the scope of the exfiltrated data.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On 12 May 2026 Foxconn acknowledged a cyberattack on its North American factories after the ransomware group Nitrogen claimed to have stolen more than eight terabytes of data, comprising approximately eleven million files, from the company. The company’s statement did not specify the exact timing of the intrusion but confirmed that some of its North American facilities were impacted. Foxconn’s spokesperson said the organization was in the process of restoring normal operations to the affected facilities and that its cybersecurity team had immediately activated response initiatives. The spokesperson also noted that multiple operational measures had been taken to ensure the continuity of production and delivery.

The ransomware group Nitrogen, identified by security researchers from Arctic Wolf, has been active since September 2024 and has targeted sectors including manufacturing, technology, construction and financial services. Researchers noted that a recent Nitrogen attack employed a Bring Your Own Vulnerable Driver technique, exploiting a vulnerable driver in Topaz Antifraud tracked as CVE‑2023‑52271 to disable antivirus tools on victim networks. Researchers from Halcyon observed that Nitrogen originally used AlphV ransomware in 2023 before evolving its tactics. Security analysts have described Nitrogen as typically avoiding direct attacks on large enterprises and instead focusing on mid‑sized companies embedded in industrial supply chains, which they view as reliable repeat targets.

According to the ransomware claim, the stolen data included schematics, project details and customer documents linked to major technology clients such as Apple, Dell, Google and Nvidia. Foxconn operates more than 230 factories and offices across twenty‑four countries worldwide, with a substantial presence in the United States, including facilities in Wisconsin, Texas and other states. In November 2025 Foxconn signed an agreement with the Wisconsin Economic Development Corp. to expand its Mount Pleasant, Wisconsin site and invest an additional $569 million, and it also entered a partnership with OpenAI to co‑design data‑center rack hardware, with Foxconn responsible for manufacturing cabling, networking, cooling and power systems. The company has stated that it is continuing to restore normal operations and that its cybersecurity team remains engaged in response actions to maintain production and delivery continuity.

Sources

Sources available to members: 7 sources.

CSIDB