Foxconn A.I CyberSecurity Scoring
Foxconn
Company Information
Website:http://www.foxconn.com
Employees number:99,265
Number of followers:478,105
NAICS:335
Industry Type:Appliances, Electrical, and Electronics Manufacturing
Homepage:foxconn.com
Foxconn Risk Score (AI oriented)
Between 0 and 549
FoxconnAppliances, Electrical, and Electronics Manufacturing
Updated:
18/06/2026
18/06/2026
547/1000
Critical
C
Foxconn Global Score (TPRM)
xxxx
FoxconnAppliances, Electrical, and Electronics Manufacturing
Score locked

FoxconnCritical
Current Score
547C (CRITICAL)
01000
7 incidents
-52.25 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
549
JULY 2026
540
JUNE 2026
544
MAY 2026
648
Ransomware
08 May 2026 • Foxconn
Foxconn, Google and Apple: Foxconn confirms cyberattack impacting North American factories
Foxconn Recovers from Nitrogen Ransomware Attack Disrupting North American Factories
537
CRITICAL-111
GOOFOXAPP1778617574
Foxconn Recovers from Nitrogen Ransomware Attack Disrupting North American Factories
Taiwanese electronics giant Foxconn has restored normal production at its North American factories following a cyberattack that disrupted operations. The company, which manufactures products for major tech firms like Apple, Google, and Microsoft, confirmed the incident but did not disclose how many of its facilities located in Wisconsin, Ohio, Texas, Virginia, Indiana, and Mexico were affected.
A Foxconn spokesperson stated that its cybersecurity team activated emergency protocols to maintain production and delivery continuity, though employees at a Wisconsin plant reported Wi-Fi outages and manual workarounds starting Friday. Computers were offline, forcing staff to rely on paper records until systems were restored.
The Nitrogen ransomware gang claimed responsibility for the attack, alleging it stole 8 terabytes of data, including sensitive technical files from multiple tech companies. Cybersecurity researchers link Nitrogen to the defunct Conti ransomware, describing it as a financially motivated group active since 2023.
Foxconn, which reported $258.3 billion in 2025 revenue, has been a frequent ransomware target. Previous attacks include a 2024 LockBit breach on its semiconductor division and incidents in Mexico in 2020 and 2022. The latest disruption underscores the persistent cyber threats facing global manufacturing supply chains.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
761
Ransomware
03 May 2026 • Foxconn
Foxconn North America, Unimed and Western Orthopaedics: Ransomware roundup: May 2026
Ransomware Attacks Rise in May 2026, With Education and Retail Sectors Hit Hardest
681
CRITICAL-80
UNIWESFOX1780562007
Ransomware Attacks Rise in May 2026, With Education and Retail Sectors Hit Hardest
Ransomware attacks increased by 3% in May 2026, with 661 incidents recorded up from 640 in April though still below the higher volumes seen earlier in the year. While overall activity remained relatively stable, certain sectors experienced sharp spikes, while others saw notable declines.
### Sector-Specific Trends
- Education saw the most dramatic surge, with attacks jumping 54% (from 13 to 20).
- Food and beverage (+80%), retail (+19%), transportation (+20%), and technology (+29%) also faced significant increases.
- Healthcare and utilities saw the steepest drops, with attacks falling 21% and 29%, respectively.
Of the 48 confirmed attacks in May:
- 35 targeted businesses, including 11 in manufacturing the most affected subsector.
- 7 hit government entities, with France, Spain, Croatia, Senegal, and Thailand among the victims.
- 5 impacted educational institutions, including Universitat de València (Spain) and Delano Public Schools (US).
- 1 affected a healthcare provider Central Medical Services of Westrock (CMSW) in the US, breached by INC, which later auctioned 200–300 GB of stolen data.
### Most Active Ransomware Groups
- Qilin led with 97 attacks, including 9 confirmed targeting entities in Australia, France, Germany, Spain, and the US.
- The Gentlemen followed with 71 attacks (4 confirmed), while DragonForce claimed 51 attacks, allegedly stealing 20.8 TB of data the largest volume reported.
- Other groups with notable activity included SafePay (+160%), Nova/RALord (+213%), Play (+325%), and Genesis (+1600%).
### Geographic Impact
The US remained the top target, accounting for 272 attacks (+6% from April), followed by Canada (31), the UK (28), and Germany (26). Spain saw a 28% increase, while the UK and Germany experienced declines.
### Data Breaches and Financial Demands
- Nearly 115 TB of data was stolen across all attacks in May.
- Manufacturing firms faced high ransom demands, including $4.48 million from an Italian company (UnoAerre Industries) and 8 TB of stolen data from Foxconn North America (claimed by Nitrogen).
- Notable breaches included:
- Unimed (Germany): 120,000+ affected, including 54,000 patients from Baden-Württemberg hospitals.
- Cardinal Services (US): Two separate attacks (June and August 2025) impacted 142,000+ people.
- Western Orthopaedics (US): 113,000+ patients notified after a 1.7 TB data theft in September 2025.
### Year-to-Date Trends
- Businesses saw 3,090 attacks (Jan–May 2026), a 13% increase from the same period in 2025.
- Healthcare recorded 208 attacks (+10% YoY), while government attacks dropped 21% (145 total).
- Education experienced 88 attacks (-25% YoY).
The data highlights shifting ransomware tactics, with threat actors increasingly targeting high-impact sectors while some industries see temporary reprieves.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
768
Vulnerability
01 May 2026 • Foxconn
Anthropic, Foxconn, 7-Eleven, Carnival Cruises and GitHub: AI helps speed cybercrime, and other cybersecurity news
AI-Powered Cybercrime Surge and Major Ransomware/Data Breaches
761
CRITICAL-7
ANTFOX7-ECARGIT1781576848
AI-Powered Cybercrime Surges as Ransomware and Data Breaches Dominate Latest Threat Landscape
The past month has seen a sharp escalation in cyber threats, with artificial intelligence (AI) accelerating cybercrime, ransomware attacks reaching new highs, and major organizations facing breaches highlighting the growing sophistication of digital threats.
### AI as a Cybercrime Accelerator
AI is increasingly being weaponized by hackers, with Verizon’s 2026 Data Breach Investigations Report revealing that nearly a third of breaches now originate from software vulnerabilities surpassing stolen passwords as the primary attack vector. Generative AI tools enable cybercriminals to rapidly identify weaknesses and develop malware, compressing the window for defenders to respond. CrowdStrike reported an 89% year-on-year increase in AI-enabled attacks in 2025, empowering both novice and advanced threat actors.
A notable case involves Anthropic’s Claude Mythos, an AI model designed to bolster cybersecurity but later found to pose risks to the systems it was meant to protect. During testing with 50 partner organizations, Mythos uncovered over 10,000 vulnerabilities in a single month. However, Anthropic suspended access to its latest models (Claude Fable 5 and Mythos 5) after U.S. authorities raised national security concerns, citing potential "jailbreaking" techniques that could expose new attack vectors.
### Ransomware Attacks Intensify
Ransomware remains a dominant threat, with Check Point Research recording a 48% surge in May 2026. The education sector was hit hardest, averaging 4,641 weekly attacks per organization a 7% increase year-on-year followed by government and telecommunications. Retail also faced significant disruptions, including a breach at 7-Eleven, where hackers leaked 9.4GB of franchisee data after failed ransom negotiations.
Manufacturing giant Foxconn, a key supplier for Apple, Google, Nvidia, and Sony, fell victim to an extortion attack in May. Hackers claimed to have stolen 11 million files, including sensitive customer data, underscoring the risks to global supply chains.
### Key Breaches and Regulatory Developments
- 23andMe (now Chrome Holding) faces legal action from California over a 2023 breach that exposed 7 million customers’ genetic and family data. The UK’s Information Commissioner’s Office previously fined the company for inadequate protections.
- Carnival Cruises disclosed a social engineering attack affecting nearly 6 million passengers, offering affected U.S. travelers two years of credit monitoring.
- GitHub suffered a breach after hackers compromised an employee’s device via a malicious Visual Studio Code extension, stealing 3,800 internal repositories though no customer-facing systems were impacted.
- U.S. Congress introduced the Great American AI Act, proposing a federal AI governance framework, including a Center for AI Standards and Innovation and fines up to $1 million per violation for non-compliance with transparency requirements.
### AI’s Dual Role in Cybersecurity
While AI fuels cybercrime, it is also becoming a critical defense tool. The World Economic Forum’s *AI and Cyber: Empowering Defenders* report found that organizations using AI for phishing detection, anomaly monitoring, and incident response reduced breach lifecycles by 80 days and cut costs by up to $1.9 million. However, sectors like education, healthcare, and NGOs where disruptions have real-world consequences remain particularly vulnerable due to resource constraints.
As AI reshapes cybersecurity, the race between attackers and defenders continues to intensify, with high-stakes breaches and regulatory shifts defining the latest threat landscape.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Vulnerability
01 May 2026 • Foxconn
Fortinet, Foxconn, Comcast, Chevron, Samsung, AT&T, Mercedes-Benz and Toyota: FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.
FortiBleed: Massive Fortinet VPN Credential Leak Exposes 74,000 Firewalls Worldwide
761
CRITICAL-7
MERCHESAMCOMFOXATTFORTOY1781713752
FortiBleed: Massive Fortinet VPN Credential Leak Exposes 74,000 Firewalls Worldwide
A newly uncovered data leak, dubbed FortiBleed, has exposed credentials for 73,932 Fortinet and FortiGate VPN firewalls across organizations globally. Security researcher Bob Diachenko discovered the breach after identifying an unsecured server containing usernames, email addresses, and plaintext passwords for high-profile targets, including Chevron, Samsung, Foxconn, Comcast, AT&T, Mercedes-Benz, Toyota, and multiple government agencies.
The dataset, analyzed by Diachenko and later confirmed by threat intelligence firm Hudson Rock, includes 21,632 unique domains spanning 194 countries, with the highest concentrations of affected devices in India, the U.S., Taiwan, Mexico, and Turkey. The compromised credentials span industries such as telecommunications, IT services, finance, healthcare, manufacturing, and critical infrastructure.
### Attack Method & Scope
Diachenko’s investigation revealed the breach was orchestrated by a Russian-speaking threat group that conducted 1.16 billion credential-stuffing attempts against 320,777 FortiGate targets and 2.1 billion attempts against 163,650 Microsoft SQL servers. The attackers used a 45-GPU cluster running Hashtopolis to crack intercepted SSL VPN authentication hashes, then leveraged the stolen credentials to infiltrate Active Directory environments.
Additional exposed files accidentally left accessible on the same server contained attack logs, scripts, and tooling, along with detailed profiles of targeted organizations, including revenue, employee counts, and industry classifications. The breach also led to full compromises of entities in Japan, Taiwan, Vietnam, Iraq, and Turkey, including a Turkish NATO defense contractor, from which classified documents were allegedly exfiltrated.
### Credential Authenticity & Origin
Cybersecurity researcher Kevin Beaumont independently verified portions of the dataset, confirming that many credentials were legitimate and that roughly 75,000 Fortinet devices most still online were affected. The data appears to have been extracted from Fortinet configuration files, as it includes email addresses and other details typically only accessible through exported configs.
Notably, many of the exposed passwords were long and complex, suggesting the attackers may have exploited previously unknown vulnerabilities or misconfigurations rather than brute-force methods. Beaumont’s analysis, based on Shodan network scans, found that nearly half of all internet-exposed Fortinet firewalls were included in the leak, with many devices exposing management interfaces directly to the web.
### Unanswered Questions
The exact method of initial compromise remains unclear. Researchers have not determined whether the data was obtained via known Fortinet vulnerabilities, a zero-day flaw, or another attack vector. Neither Diachenko, Hudson Rock, nor Beaumont have identified the original source of the configuration leaks.
Fortinet has been contacted for comment but has not yet responded. The dataset’s scale and the ongoing exposure of affected devices underscore the severity of the breach, with potential implications for supply chain security, government networks, and critical infrastructure.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
768
MARCH 2026
766
FEBRUARY 2026
766
JANUARY 2026
764
DECEMBER 2025
773
Cyber Attack
15 Dec 2025 • Foxconn
Pegatron, Foxconn, Wistron and Apple: Cyberattaque contre un partenaire Apple, des délais en perspective ?
Cyberattack on Apple's Chinese Subcontractor
762
CRITICAL-11
PEGFOXWISAPP1767108955
Cyberattack Targets Apple Supplier in China, Raising Production Concerns
In mid-December, a sophisticated cyberattack struck an undisclosed Apple subcontractor operating in China, potentially disrupting production and exposing sensitive data. While details remain scarce, the incident mirrors past disruptions—such as the 2018 malware attack on TSMC, which halted chip production for Apple—suggesting possible delays in device manufacturing.
The motives behind the attack are unclear. Hackers may have sought proprietary information on Apple products or manufacturing processes, or deployed ransomware to extort the supplier, with Apple potentially pressured to intervene to avoid production slowdowns. The compromised data could range from iPhone specifications to internal operational procedures.
Apple relies on a vast network of suppliers, including major players like Foxconn, Pegatron, and Wistron, but the identity of the targeted company has not been disclosed. The incident underscores the vulnerabilities in global supply chains, where even a single breach can ripple through production pipelines, impacting product availability. Further updates on the attack’s scope and impact are pending.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2025
773
OCTOBER 2025
772
SEPTEMBER 2025
771
MAY 2025
803
Breach
01 May 2025 • Foxconn
Fortinet, Samsung, Foxconn, Oracle and DHL: 74,000 Fortinet firewall credentials exposed in FortiBleed data leak
Russian Cybercriminal Group Exposes 74,000 Fortinet Firewall Credentials in Massive Leak
765
CRITICAL-38
SAMFOXORAFORDHL1781785487
Russian Cybercriminal Group Exposes 74,000 Fortinet Firewall Credentials in Massive Leak
A Russian-speaking cybercriminal group inadvertently exposed credentials from nearly 74,000 Fortinet firewalls and VPN gateways worldwide after leaving the data unsecured on a server. The breach, discovered by security researcher Volodymyr “Bob” Diachenko over the past weekend, was confirmed by other researchers, including Kevin Beaumont, who verified the authenticity of the leaked login details.
The compromised data, dubbed FortiBleed, includes configuration files containing sensitive information visible only from the devices themselves. The group obtained the credentials through automated large-scale harvesting, intercepting SSL VPN authentication hashes, cracking them using a 45-GPU cluster via Hashtopolis, and leveraging the passwords to infiltrate Active Directory environments. Researchers at Hudson Rock identified 73,932 unique firewall URLs across 194 countries, with many devices exposing their FortiGate Management Interface to the internet.
While Fortinet previously addressed password storage vulnerabilities in early 2025 by adopting PBKDF2 with randomized salt, many devices still use the older, weaker SHA-256 with salt method, making them susceptible to brute-force attacks. The leaked data appears to include both recently harvested credentials and older collections from prior breaches.
The breach impacts high-profile organizations, including Samsung, Siemens, Foxconn, Oracle, Accenture, DHL, Infosys, and Fortinet, as well as government agencies and critical infrastructure sectors. Notably, four organizations spanning Japan, Taiwan/Vietnam, Iraq, and Turkey were fully compromised, with a Turkish NATO defense contractor suffering exfiltration of classified defense documents.
Fortinet attributes the leak to exploited vulnerabilities and brute-force attacks, though the exact timeline of data collection remains unclear. Organizations using Fortinet devices are advised to assume compromise if their domains or IPs appear in the exposed dataset, requiring credential rotation, MFA enforcement, and system upgrades to mitigate further risks.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2020
819
Ransomware
01 Nov 2020 • Foxconn
Foxconn
Foxconn Ransomware Attack
762
CRITICAL-57
FOX2064622
Smartphone manufacturing giant Foxconn was targeted in a ransomware attack by the DoppelPaymer ransomware group in November 2020 where the attackers stole unencrypted files before encrypting devices
The attackers targeted Foxconn's North America facility and encrypted about 1,200 servers, stole 100 GB of unencrypted files, deleted 20-30 TB Of backups, and shut its website down.
The attackers demanded a ransom of about 1804.0955 BTC that's approximately $34,686,000.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Foxconn ??
What was Foxconn's A.I Rankiteo Cyber Score in July 2026 ??
What was Foxconn's A.I Rankiteo Cyber Score in June 2026 ??
What was Foxconn's A.I Rankiteo Cyber Score in May 2026 ??
What was Foxconn's A.I Rankiteo Cyber Score in April 2026 ??
What was Foxconn's A.I Rankiteo Cyber Score in March 2026 ??
What was Foxconn's A.I Rankiteo Cyber Score in February 2026 ??
What was Foxconn's A.I Rankiteo Cyber Score in January 2026 ??
What was Foxconn's A.I Rankiteo Cyber Score in December 2025 ??
What was Foxconn's A.I Rankiteo Cyber Score in November 2025 ??
What was Foxconn's A.I Rankiteo Cyber Score in October 2025 ??
What was Foxconn's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Foxconn's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Foxconn ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Foxconn's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?