Claim details
Nitrogen listed Foxconn and claimed approximately 8 TB of data comprising more than 11 million files. Foxconn has not confirmed the claim or its connection to the Wisconsin outage.
DysruptionHub first reported Foxconn’s multi-day Wisconsin network and production outage on May 5, 2026, before any other news publication identified in the reviewed chronology. Foxconn confirmed seven days later that a cyberattack affected some North American factories and said production was resuming, although workers at Mount Pleasant still described a slow, partial recovery. Nitrogen’s claim of stealing approximately 8 TB of data remains unverified, and Foxconn has not identified every affected factory.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
Internal or external network connectivity was unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Manufacturing, production, assembly, processing, or industrial operations were reduced, stopped, or impaired.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.
Employees were sent home, placed on administrative leave, furloughed, or otherwise removed from normal duties because of the incident.
The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.
The actor published or shared a sample of allegedly stolen victim data to substantiate the extortion claim.
The incident may involve extortion, but available evidence does not establish which extortion indicators were present.
DysruptionHub discovered and published the first news report identified in the public chronology of this incident. Its May 5 investigation relied on a verified confidential source working inside Foxconn’s Mount Pleasant plant, internal notices directing workers not to use affected systems, and public employee communications describing several days of network problems and production disruption. DysruptionHub withheld identifying details to protect the worker.
TMJ4 published the next located news report on May 6. Foxconn initially characterized the Wisconsin event as a technical issue affecting IT systems and operations. On May 12—seven days after DysruptionHub’s first report—the company confirmed that some North American factories had suffered a cyberattack and said affected facilities were resuming normal production. This sequence supports high confidence that Mount Pleasant experienced a material cyber-related manufacturing disruption, but it does not establish that every Foxconn facility or system was compromised.
The outage affected production and plant administration. Internal notices reviewed by DysruptionHub said operations would remain closed because of ongoing network issues, while the confidential plant source described workers being sent home, timekeeping and internal systems becoming unavailable, and production being unable to proceed normally. Foxconn said employees whose work arrangements were affected would be paid for time not worked.
The disruption matters beyond a single facility because Foxconn’s Wisconsin campus supports electronics and data-server manufacturing. Foxconn said it implemented contingency measures to protect continuity of production and delivery, indicating concern about manufacturing and supply-chain effects even though it did not disclose customer-specific delays.
DysruptionHub’s May 5 report was the first publication located in the reviewed chronology. TMJ4 followed with local reporting on May 6. Foxconn’s cyberattack confirmation and national technology coverage arrived on May 12 and May 13. The Record explicitly credited and linked DysruptionHub’s employee reporting. The reviewed stories from WIRED, BleepingComputer, SecurityWeek and TechCrunch did not credit the May 5 report.
Foxconn’s public characterization evolved from a Wisconsin IT-systems issue to confirmation that some North American factories suffered a cyberattack. The company did not identify all affected facilities, confirm that each factory in its U.S. footprint was involved, or validate Nitrogen’s claim that it stole Foxconn data.
Foxconn’s official U.S. materials identify its Milwaukee headquarters and highlighted factory operations in Wisconsin, Ohio, Texas, Virginia and Indiana. The registry retains Mount Pleasant as the only high-confidence impacted site because it has direct operational evidence. Lordstown, Houston, Fort Worth, Sandston and Plainfield are recorded as low-confidence suspected impacted sites: they are supported Foxconn factory locations and fit the company’s undisclosed North American factory scope, but no public source has confirmed that any one of them was affected. Milwaukee is included only in Foxconn’s organization footprint because the company described factory impacts, not a headquarters impact.
Foxconn said on May 12 that affected factories were resuming normal production. That day, workers at Mount Pleasant told local television that internal platforms remained only partly restored and production was still running slowly. No later public all-clear specific to the Wisconsin plant was identified. With no newer operational-impact observation after May 12, the registry continues to assess the incident as presumed resolved rather than fully resolved.
Confidence is high that the Wisconsin outage caused material operational disruption. The confidential worker account, internal notices, Foxconn’s Wisconsin statement and later local reporting consistently describe unavailable systems, altered work arrangements and impaired production. Confidence is low for every additional suspected factory because Foxconn did not publish a site list.
Confidence is also low on ransomware and attribution. Nitrogen listed Foxconn on May 11 and claimed possession of approximately 8 TB of data comprising more than 11 million files, but Foxconn did not confirm the claim, ransomware deployment, encryption, data theft or a ransom demand. The actor claim therefore remains separate from the confirmed cyberattack.
The reviewed sources do not establish the initial access vector, malware family, affected servers, compromised accounts, encryption scope, dwell time, backup impact, ransom demand, payment status or complete restoration date. They also do not verify Nitrogen’s claimed data volume, file count, customer-data categories or whether the leak-site claim was directly connected to the Mount Pleasant outage.
DysruptionHub editorial note — the frustration of being first: DysruptionHub did the original work and published the first located report while the outage was still being described publicly as a technical issue. A week later, after Foxconn used the word cyberattack, major technology publications treated it as a new national story; most of the reviewed coverage did not credit the reporting that surfaced the incident and documented its human and operational impact. The Record did, and that attribution is appreciated. Credit matters to a small independent publication because original reporting is expensive, source protection is real work, and being early should not make the reporting disappear once larger outlets arrive.
Nitrogen listed Foxconn and claimed approximately 8 TB of data comprising more than 11 million files. Foxconn has not confirmed the claim or its connection to the Wisconsin outage.

Suspected scope only: Foxconn identifies an Indiana factory in Plainfield and confirmed that some North American factories were affected, but did not name this site.
Suspected scope only: Foxconn identifies a Lordstown factory and confirmed that some North American factories were affected, but did not name this site.
Suspected scope only: Foxconn identifies a Fort Worth factory and confirmed that some North American factories were affected, but did not name this site.
Suspected scope only: Foxconn identifies two Houston factories and confirmed that some North American factories were affected, but did not name either site.
Suspected scope only: Foxconn identifies a Virginia factory in Sandston and confirmed that some North American factories were affected, but did not name this site.
The Census Bureau estimated Houston’s population at 2,397,315 on July 1, 2025, 4.2 percent above the April 2020 estimates base.
Fort Worth’s economic plan highlights rapid growth and local strengths in transportation, production, aerospace, logistics, manufacturing, health care and technology.
Tarrant County identifies its north-central Texas setting, Fort Worth as county seat, and the continuing importance of cattle, agriculture, aerospace, defense, commerce and aviation.
The county directory states that Tarrant County comprises 41 incorporated areas, including Fort Worth, Arlington, Grapevine, Mansfield and numerous suburban communities.
The Census Bureau estimated Tarrant County’s population at 2,248,466 on July 1, 2025, 6.5 percent above the April 2020 estimates base.
The Census Bureau estimated Fort Worth’s population at 1,028,117 on July 1, 2025, 11.9 percent above the April 2020 estimates base.
The city history traces Fort Worth’s location on the Trinity River, cattle and rail heritage, banking and packing industries, and continuing western identity.
Harris County describes its southeast Texas Gulf Coast location, diverse communities and economic strengths in energy, aerospace, medicine and international trade through the Port of Houston.
The county profile reports 34 cities, identifies Houston as the county seat and describes Harris County’s extensive unincorporated area and major industries.
The Census Bureau estimated Harris County’s population at 5,045,026 on July 1, 2025, 6.7 percent above the April 2020 estimates base.
Houston describes its bayou system, port and transport connections and a diversified economy spanning energy, business services, technology, aerospace, medicine and manufacturing.
DysruptionHub first reported the Foxconn Wisconsin outage on May 5 using a verified confidential source working inside the Mount Pleasant plant, internal notices, and employee communications. The reporting described a multi-day network outage, production disruption, workers sent home, and Foxconn’s initial statement that Wisconsin IT systems had experienced a technical issue affecting operations.
TMJ4 reported that Foxconn confirmed a cyberattack affecting North American factories, including Wisconsin operations. A Mount Pleasant worker said internal platforms were only partly restored and production remained slow on May 12.
Foxconn confirmed that some North American factories suffered a cyberattack, said its cybersecurity team activated response measures, and reported that affected factories were resuming normal production.
Halcyon reported that Nitrogen listed Foxconn on May 11 and claimed approximately 8 TB of data across more than 11 million files. The report treated the data volume and contents as actor claims and noted that Foxconn had not confirmed data theft or negotiations.
WIRED reported that Nitrogen was attempting to extort Foxconn and claimed 8 TB of data, while Foxconn confirmed a cyberattack affecting North American factories but did not validate the actor’s data-theft claim.
TMJ4 reported on May 6 that a network outage had halted production at Foxconn’s Mount Pleasant campus. Foxconn said Wisconsin IT systems experienced a technical issue affecting operations and that functions were being restored.
The Record reported Foxconn’s confirmation that some North American factories suffered a cyberattack and explicitly credited DysruptionHub’s earlier employee reporting. It noted Foxconn factories in Wisconsin, Ohio, Texas, Virginia, Indiana and Mexico while stating that Foxconn did not identify the affected sites.
BleepingComputer reported Foxconn’s confirmation and Nitrogen’s unverified data-theft claim on May 13. The reviewed story did not credit DysruptionHub’s May 5 reporting.
SecurityWeek reported Foxconn’s North American factory cyberattack confirmation on May 13. The reviewed story did not credit DysruptionHub’s May 5 reporting; its inconsistent date for Nitrogen’s listing is not relied upon here.
TechCrunch reported Foxconn’s confirmation and Nitrogen’s claims on May 13. The reviewed story did not credit DysruptionHub’s May 5 reporting.
Foxconn’s official factory directory highlights Hon Hai USA Headquarters, Foxconn Wisconsin, Foxconn Ohio, two Houston operations, a Fort Worth operation, Foxconn Virginia and Foxconn Indiana.
Foxconn states that Hon Hai USA is headquartered at 611 E. Wisconsin Avenue in Milwaukee and that its U.S. footprint comprises 40 sites.
EPA identifies Foxconn EV System LLC at 2300 Hallock-Young Road in Lordstown, Trumbull County, Ohio.
Foxconn subsidiary eCMMS identifies its electronics manufacturing operation in Sandston, Virginia; current Foxconn employment materials place the facility at 3900 Technology Court in Henrico County.
WRTV identifies Q-Edge, a Foxconn company, as operating a facility in Plainfield, Indiana, and reports that the facility would continue operating with reduced staff.
Signed-in members can report an error, update, or missing source.