Foxconn’s site, a Taiwanese publicly listed firm and one of the biggest electronic manufacturing companies, has been compromised by hackers.
Threat actors managed to remove unencrypted data on Foxconn's Mexican office, before they encrypted their computers.
Major Updates
- The hackers haven't leaked any financial information so far
- The assault was allegedly carried out at Ciudad Juarez, Mexico, on November 29, 2020.
- DoppelPaymer Gang is notorious for making extreme demands from their victims.
Doppelpaymer attackers told Bleeping Computer they were hitting Foxconn's North America activities, but they did not attack the whole business.
More information was also given on the subject:
"We've crypted NA section, not Foxconn as a whole; it's around 1200-1400 computers, not functioning stations. They had about 75TB of miscellaneous copies, which we might ruin
(approx 20-30TB). "
Brett Callow, a threat researcher at Emsisoft Malware Laboratory in Torrance, Bitcoin.com, told Brett Callow that Doppelpaymer had influenced various public and private institutions such as the Royal Military University of Canada, Newcastle, Pemex, and Torrance and Knoxville's cities.
Ransomware remains more and more troublesome. The average demand rose between $150k and $250k in 2018, from around $5k in 2018. And it suggests, of course, that we already have offenders who are far more empowered and more resourced.
On December, 3, Foxconn released a declaration:
We can confirm that the cybersecurity assault on November 29 centered on an information system in the USA.
We are collaborating alongside professionals and law enforcement authorities to perform inquiries and determine and put to account all the consequences of this criminal behavior.
What’s your take on the state of cybersecurity? Let’s discuss in the comments.