Skip to main content
Back to overview
Medium

Foxconn North American Factories Cyber Attack by Nitrogen Ransomware Group

Foxconn confirmed a cyber attack on some of its North American factories.

Key points

  • Cyber attack on North American factories.
  • Nitrogen ransomware group claimed responsibility.
  • 8 terabytes of sensitive data allegedly stolen.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Threat source not confirmed

03

Potential impact

Potential operational disruption

Confidentiality, Availability

Published
May 12, 2026
Updated
Jun 29, 2026
Confidence
Medium
Evidence
3 sources

Structured assessment

Signal analysis

It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch ransomware, endpoint compromise and business interruption exposure.

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data

Mentioned entities

FoxconnData DisclosureAttackNitrogen Ransomware Group FoxconnNorth AmericanThe NitrogenApple and NVIDIA. FoxconnNitrogen

Quick context

Questions about this signal

What happened in this signal?

Foxconn confirmed a cyber attack on some of its North American factories. The Nitrogen ransomware group claimed responsibility, alleging they stole 8 terabytes of sensitive data, including schematics, project details, and customer documents linked to major technology clients such as Apple and NVIDIA. Foxconn stated that affected factories were resuming normal production after the incident.

When was this signal reported?

Shadow Tier lists May 12, 2026 as the signal date.

Which organization is connected to this signal?

Foxconn is the organization connected to this public signal.

Explore Foxconn
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents