Foxconn North American Factories Cyberattack — Nitrogen Ransomware Claims 8 TB / 11M+ Documents Stolen, Including Network Topologies for AMD/Intel/Google — Threadlinqs Intelligence
As of 2026-05-30, Foxconn North American Factories Cyberattack — Nitrogen Ransomware Claims 8 TB / 11M+ Documents Stolen, Including Network Topologies for AMD/Intel/Google is a critical-severity ransomware threat attributed to Nitrogen, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-0511 · Severity: CRITICAL · Status: ACTIVE · Category: RANSOMWARE
Attribution: Nitrogen · FINANCIAL
Foxconn (Hon Hai Precision Industry) confirmed on 2026-05-12 that some of its North American factories — specifically the Mount Pleasant, Wisconsin and Houston, Texas plants — were hit by a
On Monday 2026-05-11 the Nitrogen ransomware operation added Foxconn (officially Hon Hai Precision Industry Co., Ltd. — Fortune Global 500 #28, the world's largest electronics manufacturer, with approximately 900,000 employees and ~US$260B in 2025 revenue) to its Tor-hosted data-leak site. Nitrogen's post claimed exfiltration of 8 terabytes comprising more than 11 million documents from Foxconn's North American operations, accompanied by a sample-file pack intended to validate the claim and pressure payment.
On Tuesday 2026-05-12 a Foxconn spokesperson confirmed the incident to BleepingComputer, The Register, TechCrunch and other outlets, stating: "Some of Foxconn's factories in North America suffered a cyberattack." Multiple sources subsequently identified the impacted sites as the Mount Pleasant, Wisconsin facility (which manufactures televisions and servers, not Apple devices) and the Houston, Texas factory. Foxconn stated it "immediately activated the response mechanism" and that "affected factories are currently resuming normal production," but during the disruption staff at the affected sites reportedly operated on pen-and-paper while production systems were unavailable. Foxconn declined to confirm whether customer data was actually compromised.
The sample data Nitrogen released to validate the breach reportedly contains: (a) financial documents from the Houston facility, (b) circuit-board layouts and integrated-circuit documentation, (c) temperature-sensor data from manufacturing processes, (d) technical drawings labelled with Intel, Apple, Google, Dell, AMD and Nvidia project identifiers, and (e) — most operationally significant — network-topology diagrams for AMD, Intel and Google projects. Security analyst Mark Henderson warned: "The real concern is that Google and Intel's network topologies have been stolen. Because this is an architectural map of operational infrastructure, attackers could use this data to identify vulnerabilities in data centers around the world." AppleInsider and 9to5Mac noted that despite Nitrogen's framing, the released samples do not appear to contain Apple-specific industrial-design data, and the Mount Pleasant plant does not produce iPhones.
Nitrogen first surfaced in 2023 as a malicious loader masquerading as IT-administration software (WinSCP, AnyDesk, Cisco AnyConnect, Slack, Treesize, FileZilla) distributed via malvertising and SEO-poisoning on Google Ads and Bing. Initial campaigns deployed BlackCat/ALPHV as the terminal payload, leading analysts to assess Nitrogen as an affiliate or close partner of that operation. After the ALPHV implosion (exit-scam, March 2024) Nitrogen pivoted to operating its own ransomware strain derived from the leaked Conti v2 builder, with cross-platform variants targeting Windows hosts and ESXi hypervisors. The group runs a classic double-extortion model: data exfiltration via Rclone/Mega cloud-sync, hands-on-keyboard intrusion using Cobalt Strike, Sliver and Brute Ratel C4 implants, deployment of the Nitrogen ESXi locker against virtualization fabric, and a Tor-hosted leak portal for payment pressure. In February 2026 Coveware published research demonstrating that Nitrogen's ESXi encryptor contains a cryptographic implementation bug in which the public key used for file encryption does not correspond to the operator's private decryption key, meaning encrypted ESXi virtual machines cannot be recovered even if the ransom is paid. This places victims that experienced ESXi-stage encryption in a no-win position and elevates the relative importance of resisting the data-extortion vector.
Foxconn has prior experience with ransomware: LockBit affiliates compromised Foxconn subsidiaries in 2022 (Foxconn Baja California, Tijuana plant) and 2024. The 2026 Nitrogen incident is materially worse from a supply-chain perspective because of the volume of customer-adjacent technical material in the claimed dataset — particularly the network topology maps that, if authenti
Target sectors: manufacturing, electronics, semiconductor-supply-chain, contract-manufacturing, technology
Target regions: North America, United States, Wisconsin, Texas
Related threats
- Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demands
- DragonForce Ransomware: Vishing-Driven Help Desk Social Engineering Against UK Retailers (M&S, Co-op, Harrods)
- DevMan RaaS ("Funky Mantis") Centralizes Payload Builds, Victim Management, and Affiliate Payouts, Develops SCADA-Destructive Locker
- NightSpire Ransomware — Go-Based Encryptor with .nspire Extension, RDP-First Intrusions, and Living-off-the-Land Tradecraft (Picus, Huntress, SonicWall, Broadcom)
- Black Basta Ransomware Operation - Organizational Breakdown & 2025 Shutdown
- CitrixBleed 2 (CVE-2025-5777) Weaponized by Initial Access Broker for DragonForce Ransomware Deployment
Detections & IOCs
As of 2026-08-15, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, CRITICAL, threat intelligence, cybersecurity, T1589, T1591, T1583, T1608, T1588, T1189, T1204, T1059, T1047, T1569