Nitrogen Ransomware Hits Foxconn—8TB of Apple, NVIDIA Data at Risk

Nitrogen ransomware claims 8TB stolen from Foxconn Wisconsin facility with schematics from Apple, NVIDIA, and Intel. Production was halted for a week.

In Brief

  • Nitrogen ransomware group claims it stole 8 terabytes of data — more than 11 million files — from Foxconn’s Mount Pleasant, Wisconsin facility, including schematics from Apple, NVIDIA, Intel, Google, and Dell
  • The attack halted production for nearly a week starting May 1, with workers sent home and timecard systems disabled, before operations resumed around May 12
  • AppleInsider analysis of the leaked samples suggests Apple product schematics were not among the stolen files — the Wisconsin facility primarily produces AI servers, not iPhones

Foxconn, the world’s largest contract electronics manufacturer and the company that builds essentially every iPhone, has confirmed that some of its North American factories were hit by a cyberattack in early May. The admission came after the Nitrogen ransomware group listed Foxconn on its dark web leak site on May 11, claiming to have stolen 8 terabytes of data comprising more than 11 million files from the company’s Mount Pleasant, Wisconsin facility.

The stolen archive allegedly includes confidential instructions, project documentation, and technical drawings from Intel, Apple, Google, Dell, and NVIDIA, according to the group’s leak post. WIRED first reported the breach, noting that Foxconn acknowledged some North American factories “suffered a cyberattack” and that affected facilities are “currently resuming normal production” after outages.

The scale of the claim — 8TB across 11 million files — makes this one of the largest manufacturing-sector data breaches disclosed in 2026. But the real story isn’t the volume. It’s the supply chain reach.

One Week in Mount Pleasant

The operational timeline reads like a textbook ransomware response. According to ThreatAft, the network collapse began at approximately 3:30 AM ET on May 1, when third-shift workers stopped production. First-shift workers arrived at 7 AM to find no Wi-Fi. Managers sent them home by 11 AM. For the next week, timecard terminals were dead and employees filled out paper timesheets.

An unnamed worker described the scene: they were told to turn off their computers and not log back in under any circumstances. Foxconn’s May 8 statement acknowledged an “IT systems technical issue affecting operations” but did not mention ransomware or data theft. The company confirmed on May 12 that affected factories were resuming normal production.

The Mount Pleasant facility is not just another Foxconn plant. It is the Wisconsin hub for AI server production, recently expanded with a $569 million investment announced in November. That same month, Foxconn entered an agreement with OpenAI to co-design and engineer data center racks, with Foxconn manufacturing cabling, networking, cooling, and power systems for AI infrastructure. The targeting of this specific facility — an AI hardware nerve center — may not be coincidental.

Nitrogen’s Playbook — and a Fatal Flaw

Nitrogen is a double-extortion ransomware group first identified in mid-2023 by Sophos X-Ops, initially operating as an initial access malware campaign using malvertising — fake Google and Bing ads for software tools — to compromise business networks. The group has since evolved into a full extortion outfit. Trend Micro and Sophos research shows Nitrogen infection chains leading to BlackCat (ALPHV) ransomware deployment, suggesting the group may act as an initial access broker for the broader ransomware ecosystem.

A recent Nitrogen attack used a technique known as Bring Your Own Vulnerable Driver (BYOVD), exploiting a vulnerable driver in Topaz Antifraud tracked as CVE-2023-52271 to disable antivirus tools on the victim network. The group also spends weeks inside networks quietly staging data before any visible disruption, maximizing extortion leverage. In January 2026, researchers observed Nitrogen blocking IP addresses of failed negotiators — a countermeasure designed to undermine skilled ransom negotiators.

But Nitrogen has a critical weakness. Per Coveware, the group’s ESXi encryptor corrupts file public keys during encryption, meaning victims who pay the ransom may still be unable to decrypt their files. This flaw turns a double-extortion scheme into something closer to pure data theft — the encryption side is unreliable, which pushes the incentive structure further toward leaking stolen data rather than negotiating.

Ismael Valenzuela, VP of threat intelligence research at Arctic Wolf, told Cybersecurity Dive that Nitrogen deliberately targets mid-sized companies tied to industrial operations and supply chains rather than large enterprises directly. These are businesses that keep supply chains running but often lack the depth of security resources found in large enterprises, making them a reliable and repeatable target. Foxconn, with 230 factories across 24 countries, presents an unusual target for a group that typically avoids Tier-1 enterprises — suggesting either a shift in ambition or an opportunistic entry through a softer access point.

Apple Is Probably Fine — This Time

While the Nitrogen leak post names Apple among the affected customers, AppleInsider analyzed the sample files released by the group and found no evidence of Apple schematics, product documentation, or quality control data. This aligns with the nature of the Mount Pleasant facility, which primarily produces televisions and AI data servers rather than Apple devices. Foxconn’s Apple-facing manufacturing largely occurs in separate facilities in China and India, typically protected by internal VPNs.

The sample files instead contained financial documents related to Foxconn’s Houston, Texas facility, network topology documentation for AMD, Intel, and Google projects, and electrical engineering team files — board layouts, integrated circuit documentation, and temperature sensor designs. Analyst Mark Henderson told AppleInsider that the topology specs for Google and Intel are the real concern because these are architectural maps of live infrastructure that could enable further attacks.

This distinction matters for the risk assessment. Apple’s consumer product designs appear to have been shielded by Foxconn’s network segmentation between facilities. But the Google and Intel data center topology diagrams — architectural maps of live infrastructure — represent exactly the kind of operational intelligence that enables follow-on attacks. A ransomware group that knows your network layout has a significant advantage for any future intrusion.

Supply Chain Attacks Keep Scaling

Foxconn is no stranger to ransomware. A Foxconn subsidiary, Foxsemicon, was hit by a ransomware gang in 2024. An Apple assembler in China was targeted in December 2025, and Luxshare was hit in January 2026. The pattern is accelerating. This year has already seen supply chain breaches at Instructure’s Canvas platform and Rhode Island’s $12M Deloitte settlement over a 2024 ransomware incident, and now the world’s largest electronics manufacturer.

The Foxconn breach follows a broader 2026 trend of ransomware groups moving up the supply chain. When SecurityWeek asked Foxconn about the Nitrogen claims, the company confirmed the attack but declined to comment on the specifics of the data theft allegations. The group has published screenshots as proof, and cybersecurity analysts who reviewed the sample files confirmed that at least some of the claims appear legitimate.

For the major tech companies named in the leak — Apple, NVIDIA, Intel, Google, Dell — the immediate risk is not direct data loss but the downstream exposure of proprietary designs and infrastructure topology. Foxconn’s statement that it implemented multiple operational measures to ensure the continuity of production and delivery suggests the company prioritized getting lines running again over full forensic assessment, a common trade-off in manufacturing ransomware incidents where every hour of downtime carries significant cost.

FAQ

What is the Nitrogen ransomware group?

Nitrogen is a double-extortion ransomware group first identified in 2023. The group steals data before encrypting victim systems, using both threats of data leaks and encryption to pressure victims into paying. Nitrogen has ties to the ALPHV/BlackCat ransomware ecosystem and typically targets mid-sized companies in manufacturing, technology, and financial services.

Was Apple product data actually stolen?

AppleInsider analyzed the sample files released by Nitrogen and found no evidence of Apple schematics, product documentation, or quality control data. The Mount Pleasant facility primarily produces AI servers and televisions, not Apple devices. Apple’s manufacturing occurs at separate Foxconn facilities in China and India.

What is BYOVD and how did Nitrogen use it?

Bring Your Own Vulnerable Driver is a technique where attackers exploit a legitimately signed but vulnerable kernel driver to disable antivirus software. Nitrogen exploited CVE-2023-52271, a vulnerability in the Topaz Antifraud driver, to turn off security tools on the victim network before deploying ransomware.

Can Foxconn recover the encrypted files by paying the ransom?

Probably not. According to Coveware, Nitrogen’s ESXi encryptor corrupts file public keys during encryption, meaning victims who pay may still be unable to decrypt their files. This flaw effectively turns the attack into pure data theft rather than a standard ransom scenario.

How big is the Foxconn breach?

Nitrogen claims to have stolen 8 terabytes of data across more than 11 million files. If confirmed, this would rank among the largest manufacturing-sector data breaches disclosed in 2026. The stolen data reportedly includes confidential instructions, project documentation, and technical drawings from Foxconn customers including Intel, Apple, Google, Dell, and NVIDIA.

Leave your vote