Advantest confirms personal data was stolen in February ransomware attack
Japanese chip-testing giant Advantest says attackers who deployed ransomware in February also stole personal data, including Social Security, passport and medical information.
At a glance
- Attackers breached Advantest's network on February 15, 2026 and deployed ransomware.
- Notification letters dated October 6 confirm theft of contact details, birth dates, SSNs, ID and passport numbers, medical and financial data.
- State filings show more than 500 California residents affected; the total has not been disclosed.
- No ransomware group has claimed the attack; Kroll monitoring is offered until January 4, 2027.
Advantest, the Japanese maker of automated test equipment used by chipmakers such as Intel and Samsung, has confirmed that personal information was stolen in the ransomware attack it suffered in February 2026. According to BleepingComputer and SecurityWeek, data breach notification letters dated October 6 tell recipients that their personally identifiable information was extracted from the company's servers.
What happened
BleepingComputer reports that a threat actor breached Advantest's network on February 15, 2026 and gained access to some systems. At the time, the company said the attackers had deployed a ransomware payload but that it could not yet determine whether customer or employee data had been affected. The new notifications close that question roughly eight months later.
"The data extracted from our servers included PII (personally identifiable information) belonging to you," the notice states, according to BleepingComputer. Advantest says it has no information indicating that the stolen data has been published or misused, but acknowledges that recipients face an elevated risk of identity theft and fraud.
What data was exposed
According to the notification, the exposed information includes contact details, dates of birth, Social Security numbers, national ID numbers, driver's license numbers, passport numbers, medical information, financial information and other identification numbers. The exact data set varies by individual.
Who is affected
Advantest has not disclosed the total number of affected people. SecurityWeek reports that regulatory filings show more than 500 California residents, 14 Massachusetts residents and 8 Vermont residents were affected. BleepingComputer notes it is unclear whether the victims are customers, employees, partners or a mix, and says the company had not responded to questions about the scale of the breach at the time of publication.
No ransomware group has publicly claimed responsibility. BleepingComputer said it found no leak-site claims naming Advantest when it published its report.
What to do
Advantest is offering affected individuals 18 months of free identity theft, credit and web monitoring through Kroll, with enrollment open until January 4, 2027. Recipients are advised to monitor bank and financial statements, report unknown transactions to their banks, and treat unsolicited emails and text messages with caution, since stolen personal data is often reused in targeted phishing. Organizations that share data with Advantest as partners or suppliers may want to confirm with the company whether their personnel are among those notified.
Sources
- Advantest confirms personal information stolen in ransomware attack — BleepingComputer
- Advantest Discloses Data Breach Months After Ransomware Attack — SecurityWeek
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



