Cybersecurity incident forces largest US steelmaker to take some operations offline

Avatar

North Carolina-based steel company Nucor said it temporarily halted production operations at some locations because of a recent cybersecurity incident and is working to restart them.

In an 8-K filing with federal regulators, Nucor said the incident involved “unauthorized third party access to certain information technology systems” but did not explain further. 

The company “began promptly taking steps to contain and respond to the incident, including activating its incident response plan, proactively taking potentially affected systems offline and implementing other containment, remediation, or recovery measures,” the filing said.

Nucor did not specify which facilities were affected. The company said it only halted some operations “in an abundance of caution.” From recycling centers to large plants, the company operates at about 300 locations overall.

Headquartered in Charlotte, Nucor reported sales of $7.83 billion in the first quarter of 2025 and calls itself “North America’s largest steel manufacturer and recycler,” with about 25,000 employees. Industry analysts list it as one of the top 20 in the world.

One of its largest projects is a $3 billion facility under construction in West Virginia. 

Large manufacturers are under constant pressure from malicious hackers, whether the interest is financial cybercrime, intellectual property theft or even nation-state espionage.

Recent cybersecurity-related 8-K filings by U.S. manufacturers include medical technology company Masimo, industrial sensor maker Sensata, home appliance company National Presto Industries and semiconductor firm Microchip Technology.

The trend applies globally, with industrial firms in the United Kingdom and Switzerland among those reporting cybersecurity incidents over the past year.

CybercrimeIndustryNewsNews Briefs
Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Joe Warminsky

is the news editor for Recorded Future News. He has more than 25 years experience as an editor and writer in the Washington, D.C., area. He previously he helped lead CyberScoop for more than five years. Prior to that, he was a digital editor at WAMU 88.5, the NPR affiliate in Washington, and he spent more than a decade editing coverage of Congress for CQ Roll Call.

 

Total
0
Shares
Previous Post

Xinbi Telegram Market Tied to $8.4B in Crypto Crime, Romance Scams, North Korea Laundering

Next Post

British retailer M&S reportedly set to claim £100 million from insurers after cyberattack

Related Posts

Coinbase Initially Targeted in GitHub Actions Supply Chain Attack; 218 Repositories’ CI/CD Secrets Exposed

The supply chain attack involving the GitHub Action "tj-actions/changed-files" started as a highly-targeted attack against one of Coinbase's open-source projects, before evolving into something more widespread in scope. "The payload was focused on exploiting the public CI/CD flow of one of their open source projects – agentkit, probably with the purpose of leveraging it for further compromises,"
Avatar
Read More