Advantest confirms PII stolen in February ransomware attack
Advantest Corporation has started notifying people whose personal data was stolen in a ransomware attack on its network earlier this year, BleepingComputer reports.
The Japanese company builds automated test equipment for the semiconductor industry and sells it worldwide. The attack happened on February 15, 2026. A threat actor got into Advantest's network, reached some of its systems and deployed a ransomware payload.
In its first disclosure, Advantest confirmed the intrusion and the encryption, but said it did not yet know whether customer or employee data had been affected. That question now has an answer.
Notification confirms data theft
A data breach notification dated October 6, 2026, says the attackers took data from the company's servers.
"In February 2026, Advantest became aware of a cybersecurity incident in which an unauthorized third party accessed Advantest systems and extracted some data from our servers," the notice reads.
It goes on to tell recipients that "the data extracted from our servers included PII (personally identifiable information) belonging to you."
The exposed information covers a wide range of sensitive records:
- contact information
- date of birth
- Social Security Number (SSN)
- national ID number
- driver's license
- passport number
- medical information
- financial information
- other ID numbers
The notification does not say whose data was taken. The affected people could be customers, employees, business partners, or a mix of these groups. Advantest also has not said how many individuals are affected. BleepingComputer asked the company about this but had not received a reply at the time of publication.
No sign of misuse so far
Advantest says it has no information showing that the stolen data has been leaked or misused. The company does acknowledge that the people affected now face a higher risk of identity theft and fraud.
To reduce that risk, it is offering 18 months of free identity theft, credit and web monitoring through Kroll. The letter includes enrollment instructions, and recipients have until January 4, 2027, to activate the service.
The company also advises recipients to:
- watch their accounts and financial statements closely for suspicious activity
- report any transactions they do not recognize to their bank
- be wary of phishing attempts and avoid clicking links or opening attachments in unexpected messages
- never send money or share sensitive information in response to requests by email or text
When BleepingComputer published its report, no ransomware group had publicly claimed the Advantest attack.
Our Take
The Advantest case follows a familiar pattern. A company first confirms that ransomware hit its systems, and only months later says that personal data was actually stolen. Almost eight months passed between the February intrusion and the October notification. For the people affected, that is a long time in which their data may have been in criminal hands without their knowledge. Other recent incidents, such as the suspected ransomware attack on Osaka Metropolitan University, are also still in the early stage, where the full scope is unclear.
The mix of exposed data is what stands out here. SSNs, passport numbers and medical records together make a valuable package for identity fraud. Unlike a password, none of these can easily be changed. The lack of a public claim from a ransomware gang suggests the data may not have been dumped on a leak site. But it does not rule out a private sale or later publication, so recipients should not treat the silence as reassurance.
Recipients should be careful with any message that refers to the breach, because criminals often build phishing lures around incidents like this. A tool such as a scam link checker can help before clicking. It is also worth watching whether Advantest discloses the number of victims, as other firms have done in recent breach notifications, and whether a ransomware group eventually takes credit for the attack.
