Foxconn said operational IT issues disrupted its Mount Pleasant, Wisconsin campus, where workers reported a broad network outage affecting Wi‑Fi, core infrastructure, and timekeeping systems as production was gradually restored. The Nitrogen ransomware group later claimed responsibility on its extortion site, alleging it stole 8TB of data spanning more than 11 million files from the Racine County facility, including assembly instructions, hardware schematics, and data center topology diagrams tied to customers such as Apple, Intel, Google, NVIDIA, and Dell. Foxconn has not verified the authenticity of the leaked samples or disclosed any ransom demand, and reports said the incident may also have affected a Foxconn site in Houston.
The claimed breach adds to a pattern of ransomware incidents affecting Foxconn manufacturing operations. In 2022, Foxconn confirmed a ransomware attack at its Tijuana, Mexico plant that disrupted production and was claimed by LockBit, with the company saying recovery was underway and overall business impact would be limited. That attack followed a 2020 intrusion at Foxconn’s Ciudad Juárez facility attributed to DoppelPaymer, underscoring repeated targeting of the company’s production sites and raising renewed supply-chain and industrial espionage concerns around its AI server and electronics manufacturing operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Foxconn confirmed operational IT issues at its Wisconsin site and said production was being gradually restored, but it did not verify the authenticity of the leaked samples or disclose any public ransom demand. The incident raised concerns about supply-chain and industrial espionage risks because the site supports AI server assembly and liquid-cooling testing.
By 2026-05-11, the Nitrogen ransomware group had listed Foxconn on its dark web extortion site, claiming it stole 8 terabytes of data comprising more than 11 million files from the company's Racine County, Wisconsin facility. The alleged haul included assembly instructions, hardware schematics, and data center topology diagrams tied to Apple, Intel, Google, NVIDIA, and Dell.
On 2026-05-01, Foxconn's Mount Pleasant, Wisconsin campus experienced a major outage, with workers reporting a full network collapse affecting Wi‑Fi, core infrastructure, and timekeeping systems. The disruption may also have affected a Foxconn facility in Houston, Texas.
On or around 2022-06-02, Foxconn confirmed that its Tijuana, Mexico production plant had been hit by a ransomware attack in late May. The company said its cybersecurity team was executing a recovery plan and that factory operations were gradually returning to normal with limited overall business impact.
On 2022-05-31, the LockBit ransomware gang claimed responsibility for a ransomware attack on Foxconn's strategic factory in Tijuana, Mexico. The group threatened to leak allegedly stolen data unless a ransom was paid by 2022-06-11.
In December 2020, the DoppelPaymer ransomware group claimed it attacked Foxconn's CTBG MX facility in Ciudad Juárez, Mexico, and demanded $34 million. This was described as an earlier ransomware incident affecting Foxconn's Mexico operations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
thecybersecguru.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourceindustryweek.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.