- Joined
- Jan 20, 2026
- Messages
- 345
- Reaction score
- 2,767
Foxconn has recognized a cyber attack on factories in North America.

A large production contractor of Apple was again the target of ransomware. The Nitrogen group said it stole eight terabytes of data from Foxconn, including schemes and customer projects, including Dell, Google, Apple and Nvidia.
Foxconn did not confirm the reliability of the attacks, but admitted that several North American factories of the company have been hit by a cyber attack in recent days. The manufacturer told WIRED that the affected enterprises are already restoring normal output after failures.
Foxconn looks like a particularly attractive target for ransomware not only because of the scale of the business. The company manages divisions and subsidiaries around the world, which means it stores not only its own developments, but also confidential customer materials. Foxconn releases electronic components and entire devices for the largest technology brands, including the iPhone for Apple.
Recorded Future analyst Allan Liska noted that ransomers are increasingly choosing victims that can affect supply chains, whether physical production or software. According to the expert, the attack on Foxconn does not look unexpected: the manufacturer works with sensitive data of many companies around the world.
Nitrogen added Foxconn to its website with leaks on Monday. The group appeared in 2023 and does not belong to the most famous ransomware operators, but continues to regularly attack organizations, especially in North America and Western Europe. Nitrogen activity increased markedly at the end of 2024, and the researchers also associate the group with the infamous ALPHV/BlackCat
Vice-President for intelligence at Flashpoint Ian Gray said that the company’s experts first noticed Nitrogen’s activity in 2024 during an attack on Control Panels USA. Since the launch, the group, according to Flashpoint, has attacked about 50 victims, most often from the manufacturing, technology and retail sectors. Production has long been one of the main goals of ransomware.
Foxconn has already faced major attacks. In December 2020, the DoppelPaymer group attacked the company’s enterprise in Mexico and demanded 1 804 bitcoins, which at that time was about $ 34 million. In May 2022, LockBit hit another Mexican factory Foxconn and disrupted production. In 2024, LockBit attacked a subsidiary of Foxsemic Integrated Technology, declaring a hack and leak.
Nitrogen uses not only the threat of publishing stolen files, but also the classic encryption of the victim’s systems. The researchers note that the grouping ransomware program is built on a widely processed Conti 2 code, however, there is a serious defect in the encryption mechanism: after blocking, the data cannot be decrypted even if the attackers themselves want. It is not yet known whether this feature played a role in the Foxconn reaction to the current incident.
Foxconn has become an attractive target for ransomware precisely because of the role in the world electronics. The company works with the largest technology brands and can store not only its own data, but also customer materials, including schemes and project information. According to experts, criminal groups are increasingly choosing victims, the attack on which can affect production chains.

A large production contractor of Apple was again the target of ransomware. The Nitrogen group said it stole eight terabytes of data from Foxconn, including schemes and customer projects, including Dell, Google, Apple and Nvidia.
Foxconn did not confirm the reliability of the attacks, but admitted that several North American factories of the company have been hit by a cyber attack in recent days. The manufacturer told WIRED that the affected enterprises are already restoring normal output after failures.
Foxconn looks like a particularly attractive target for ransomware not only because of the scale of the business. The company manages divisions and subsidiaries around the world, which means it stores not only its own developments, but also confidential customer materials. Foxconn releases electronic components and entire devices for the largest technology brands, including the iPhone for Apple.
Recorded Future analyst Allan Liska noted that ransomers are increasingly choosing victims that can affect supply chains, whether physical production or software. According to the expert, the attack on Foxconn does not look unexpected: the manufacturer works with sensitive data of many companies around the world.
Nitrogen added Foxconn to its website with leaks on Monday. The group appeared in 2023 and does not belong to the most famous ransomware operators, but continues to regularly attack organizations, especially in North America and Western Europe. Nitrogen activity increased markedly at the end of 2024, and the researchers also associate the group with the infamous ALPHV/BlackCat
Vice-President for intelligence at Flashpoint Ian Gray said that the company’s experts first noticed Nitrogen’s activity in 2024 during an attack on Control Panels USA. Since the launch, the group, according to Flashpoint, has attacked about 50 victims, most often from the manufacturing, technology and retail sectors. Production has long been one of the main goals of ransomware.
Foxconn has already faced major attacks. In December 2020, the DoppelPaymer group attacked the company’s enterprise in Mexico and demanded 1 804 bitcoins, which at that time was about $ 34 million. In May 2022, LockBit hit another Mexican factory Foxconn and disrupted production. In 2024, LockBit attacked a subsidiary of Foxsemic Integrated Technology, declaring a hack and leak.
Nitrogen uses not only the threat of publishing stolen files, but also the classic encryption of the victim’s systems. The researchers note that the grouping ransomware program is built on a widely processed Conti 2 code, however, there is a serious defect in the encryption mechanism: after blocking, the data cannot be decrypted even if the attackers themselves want. It is not yet known whether this feature played a role in the Foxconn reaction to the current incident.
Foxconn has become an attractive target for ransomware precisely because of the role in the world electronics. The company works with the largest technology brands and can store not only its own data, but also customer materials, including schemes and project information. According to experts, criminal groups are increasingly choosing victims, the attack on which can affect production chains.