Advantest confirms data stolen in February ransomware attack
According to BleepingComputer, Advantest Corporation has begun notifying individuals that a ransomware attack in February 2026 led to the theft of their personal data. The Japanese semiconductor test equipment maker confirmed the data theft in a breach notification dated October 6, 2026, roughly eight months after the intrusion. The number of affected people has not been disclosed.
What we know about the Advantest data breach
- On February 15, a threat actor breached Advantest’s network and accessed some systems, according to the company’s earlier disclosure as reported by BleepingComputer.
- That earlier disclosure said a ransomware payload was deployed, but the company could not yet say whether customer or employee data was affected.
- The October 6 notification now confirms that an unauthorized third party extracted some data from its servers, including personally identifiable information (PII).
- Advantest says it has no information that the stolen data has been leaked or misused, while acknowledging an elevated risk of identity theft and fraud.
The company offers affected individuals 18 months of free identity theft, credit and web monitoring through Kroll. Recipients have until January 4, 2027 to activate it.
Who is affected and what data was exposed
The notification lists these data types:
- Contact information
- Date of birth
- Social Security number (SSN)
- National ID number
- Driver’s license number
- Passport number
- Medical information
- Financial information
- Other ID numbers
It is not clear whether the data belongs to customers, employees, partners or a mix of these groups. Not every recipient necessarily had every data type exposed; the company’s letter is the authoritative source for each individual.
What has not been confirmed
- Number of victims: not disclosed. BleepingComputer asked Advantest and had not received a reply at publication.
- Attacker identity: not disclosed. BleepingComputer found no public claim from a ransomware group targeting Advantest.
- Leak status: Advantest says it has no information of a leak or misuse, but that is a statement about what the company knows, not proof the data is safe.
- Entry point and ransomware family: not disclosed.
Why this matters
Analysis, not new reporting. The mix of SSNs, passport and national ID numbers, medical and financial details is the combination used for identity fraud and tailored phishing, and it does not expire quickly. A delay of this length between intrusion and confirmation is also a reminder that the full impact of a ransomware incident can take months to establish. Advantest supplies equipment to the semiconductor industry, so partners and suppliers that exchanged personal or contact data with it may want to check whether they are on the notification list.
What to do if you received a letter
- Enroll in the offered Kroll monitoring before January 4, 2027.
- Monitor bank, card and credit accounts closely and report unknown transactions to your bank.
- Consider a credit freeze or fraud alert, which is general identity-theft guidance and not part of the company’s notice.
- Treat unexpected email or text messages as suspicious: do not click links or open attachments, and never send money or share sensitive information in response.
What security teams should do
- Check whether your organization shares employee, customer or contact data with Advantest, and ask for written confirmation of whether your data was involved.
- Brief staff who may be affected about targeted phishing that references the breach or the monitoring offer. Verify any such message through the official notification channel.
- If you are a vendor of Advantest, review the data you hold on its behalf and the access it has to your systems, and rotate shared credentials if there is any doubt.
- Watch for credential-reuse and account-takeover attempts against affected employees, and consider requiring password resets where personal data may have been exposed.
- Use this as a prompt to test your own notification timeline: could you confirm data theft, and name what was taken, soon after a ransomware intrusion?
This post will be updated if Advantest discloses the number of affected individuals or if a ransomware group claims the attack.
