Hon Hai Precision Industry Co., Ltd.
Incident posture
Linked entities
- Victim
- Hon Hai Precision Industry Co., Ltd.
- Threat actors
- 1 actor
- Sources
- 7 sources
Timeline
Summary
Hon Hai Precision Industry Co., Ltd. (Foxconn) experienced a cyberattack claimed by the ransomware group Nitrogen, which asserted theft of approximately eight terabytes of data comprising around eleven million files, including schematics from major technology partners. The attack affected some of the company's North American facilities, prompting operational measures to restore normal operations while investigators assessed the scope of the exfiltrated data.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On 12 May 2026 Foxconn acknowledged a cyberattack on its North American factories after the ransomware group Nitrogen claimed to have stolen more than eight terabytes of data, comprising approximately eleven million files, from the company. The company’s statement did not specify the exact timing of the intrusion but confirmed that some of its North American facilities were impacted. Foxconn’s spokesperson said the organization was in the process of restoring normal operations to the affected facilities and that its cybersecurity team had immediately activated response initiatives. The spokesperson also noted that multiple operational measures had been taken to ensure the continuity of production and delivery.
The ransomware group Nitrogen, identified by security researchers from Arctic Wolf, has been active since September 2024 and has targeted sectors including manufacturing, technology, construction and financial services. Researchers noted that a recent Nitrogen attack employed a Bring Your Own Vulnerable Driver technique, exploiting a vulnerable driver in Topaz Antifraud tracked as CVE‑2023‑52271 to disable antivirus tools on victim networks. Researchers from Halcyon observed that Nitrogen originally used AlphV ransomware in 2023 before evolving its tactics. Security analysts have described Nitrogen as typically avoiding direct attacks on large enterprises and instead focusing on mid‑sized companies embedded in industrial supply chains, which they view as reliable repeat targets.
According to the ransomware claim, the stolen data included schematics, project details and customer documents linked to major technology clients such as Apple, Dell, Google and Nvidia. Foxconn operates more than 230 factories and offices across twenty‑four countries worldwide, with a substantial presence in the United States, including facilities in Wisconsin, Texas and other states. In November 2025 Foxconn signed an agreement with the Wisconsin Economic Development Corp. to expand its Mount Pleasant, Wisconsin site and invest an additional $569 million, and it also entered a partnership with OpenAI to co‑design data‑center rack hardware, with Foxconn responsible for manufacturing cabling, networking, cooling and power systems. The company has stated that it is continuing to restore normal operations and that its cybersecurity team remains engaged in response actions to maintain production and delivery continuity.
Sources
Sources available to members: 7 sources.