Foxconn confirmed this week that a cyberattack disrupted operations across its North American factories. A spokesperson acknowledged the incident, then promptly declined to say how many sites were affected, what kind of intrusion it was, or who was behind it. The company has plants in Wisconsin, Ohio, Texas, Virginia, Indiana, and across Mexico, so the operational footprint of that “no comment” is substantial.

Foxconn manufacturing facility exterior
Foxconn’s North American plants span six U.S. states and Mexico.

It would be tempting to file this next to the rest of 2026’s manufacturing cybersecurity incidents and move on. That would be a mistake. Foxconn lands the same week Cisco Talos published a blunt reminder that nation-state intrusions are a different IR problem entirely, and that the playbook most security teams reach for in a ransomware case will actively work against them in a state-sponsored one. We don’t know yet which kind of adversary owns Foxconn’s factory floor. Most companies wouldn’t be ready for either.

Two attacks. Two completely different response problems.

A ransomware response, at its core, is a clock. Find the encryptor, scope what’s encrypted, isolate, restore, negotiate or don’t, and write the postmortem. Talos’s argument is that state-sponsored actors invert nearly every assumption in that sequence. They aren’t looking to be noticed. They don’t want your money. They want persistence, telemetry, and intellectual property, and they will wait you out for years if you let them.

The instinct in a ransomware case is to move fast: isolate affected segments, rotate credentials, push out IOCs, get business back online. In a state-sponsored case, the same speed will burn your visibility. The moment you start swinging a hammer, the actor disappears into a different beachhead, and all you’ve accomplished is teaching them which of your detections fired. Foxconn’s terse statement, whatever its motivation, isn’t unusual for that reason. The companies that handle these well are the ones that resist the urge to issue a satisfying first response.

Manufacturing makes the picture worse. A factory floor is not a corporate LAN. Industrial control systems run on protocols that were never designed to be reviewed by an EDR. Patch windows are scheduled months out, sometimes never. The OT side of the house often reports to plant operations rather than the CISO. When a threat actor pivots from IT to OT, the team that needs to respond may not even be on the same call.

Why your cybersecurity plan is probably wrong for both

Most incident response plans are built on a comfortable fiction: that the company will be hit by a single, recognizable adversary using a known technique, and that the response team will identify it in the first 24 hours. Real intrusions don’t accommodate this. A campaign can start as a commodity infostealer dropped on a salesperson’s laptop and end with an APT operator quietly enumerating PLC firmware in a production line. The cybersecurity team that classifies the first event as “low” because the user denied clicking the link has already lost chain of custody on the second one.

A single IR playbook cannot cover both ransomware and state-sponsored campaigns. The triage decisions differ. The comms strategy differs. Law enforcement engagement differs. Eviction strategy differs profoundly. Treating them as one problem is how organizations end up bringing systems back online while the actor is still resident, which is the failure pattern that produced the second Instructure breach.

What to actually do this quarter

Start by writing down what your team would do in the first hour of an incident that doesn’t look like ransomware. Most plans have a flow for ransomware and a hand-wave for everything else. If your runbook says “engage external IR” and nothing more, that’s the gap. Have at least two named retainers on file, with one of them experienced in OT or nation-state work, depending on your business. Test the call tree quarterly. Most teams discover their incident contact list is stale on the day it matters.

Segment ruthlessly between IT and OT. The threat protection controls you trust on the corporate LAN, from EDR to brute-force lockout to firewall egress filtering, are usually absent or degraded on the plant floor. That asymmetry has to be reflected in your network design. Treat every link between corporate and operational networks as a hostile boundary. Restrict it with explicit allowlists, log every transit, and alert on anything outside that allowlist regardless of severity. Edge tools that block scanning and brute-force traffic, including open-source options like IPBan or its commercial sibling IPBanPro, are useful at the OT/IT seam where attackers often try to enumerate quietly before pivoting.

Build threat detection that survives an adversary who knows you’re watching. Hunt for low-and-slow signals: scheduled tasks created outside maintenance windows, service accounts logging in from new subnets, unsigned binaries running on jump hosts, DNS to newly registered domains from servers that should never beacon out. Defense in depth is not a slogan; it’s the working assumption that any one of your controls has already been bypassed. Build the next layer accordingly. Security hardening at the identity and network seams pays back disproportionately here.

Separate your eviction plan from your restoration plan. Talos’s point lands hardest here. Restoring services makes the business happy. Eviction is what actually ends the incident. If your IR plan treats them as the same milestone, you are guaranteed to do one of them poorly. The teams that survived recent ShinyHunters re-entries learned this the expensive way.

Frequently Asked Questions

How do you tell a ransomware incident from a state-sponsored one early on?
Look for the absence of noise. State actors avoid encryption, ransom notes, and obvious lateral movement. If the first IOC is a single dormant beacon on a high-value host with no follow-on activity, treat that hypothesis seriously before you start touching the environment.
Should manufacturers have a separate OT incident response team?
At minimum, a dedicated OT runbook with named on-call engineers from plant operations and an IR retainer experienced with industrial control systems. The corporate SOC rarely has the protocol knowledge to triage a PLC alert in the moment.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.