Foxconn acknowledged that several of its North American factories suffered a cyberattack in recent days, after the Nitrogen ransomware group listed the manufacturer on its breach site Monday and claimed to have stolen 8 terabytes of data. The company said the affected factories are currently resuming normal production following outages.

The Nitrogen group asserted that the stolen data includes schematics and project details belonging to Foxconn customers Dell, Google, Apple, and Nvidia, and is attempting to extort the company. Foxconn manufactures electronic components and entire devices for major technology firms, including iPhones for Apple, and its divisions and subsidiaries worldwide hold its own and its customers' intellectual property.

"Ransomware groups are increasingly targeting victims that can impact the supply chain, whether it is physical or software. So it's unsurprising that a company like Foxconn would be targeted, since it does manufacturing and holds sensitive data for so many companies around the world," said Allan Liska, a threat intelligence analyst at Recorded Future.

The Nitrogen ransomware group emerged in 2023 and has been steadily active with some spikes, including at the end of 2024. It typically targets victims in North America and Western Europe and has connections to the ALPHV/BlackCat ransomware group.

"While reports indicate that Nitrogen has been active since 2023, our first observation of their activity was in 2024, targeting Control Panels USA. We have observed approximately 50 victims since launching, primarily targeting manufacturing, technology, and retail. Manufacturing is one of the most-targeted sectors for ransomware in general," said Ian Gray, vice president of intelligence at Flashpoint.

Nitrogen often deploys traditional ransomware that encrypts a target's systems in addition to threatening to release stolen data. Researchers say the group's ransomware program was built off repurposed "Conti 2" code, and its encrypting mechanism has a design flaw that makes encrypted data impossible to decrypt.

Foxconn has been targeted by ransomware operations multiple times in recent years. In December 2020, the DoppelPaymer ransomware group demanded 1,804 bitcoin, worth roughly $34 million at the time, from a Foxconn facility in Mexico. In May 2022, the LockBit group attacked a Foxconn facility in Mexico and disrupted production. Also in 2024, LockBit attacked the Foxconn subsidiary Foxsemicon Integrated Technology with defacements and data breach claims.