Advantest Corporation, the Japanese maker of automated test equipment (ATE) used across the semiconductor industry, has confirmed that attackers stole personal data during the ransomware attack it disclosed in February 2026. In a notification letter dated October 6, 2026 and filed with the California Attorney General, the company says an "unauthorized third party accessed Advantest systems and extracted some data from our servers," and that the data included personally identifiable information (PII) of the people receiving the letter. Advantest has not said how many people were affected. BleepingComputer asked and had not received an answer at publication. Filings by its US subsidiary, Advantest America, Inc., with the California and Vermont Attorneys General point to a mostly US-based group of victims. Plaintiff law firms say those filings list Social Security numbers and financial account data. No ransomware group has publicly claimed the attack.
What Happened
The timeline the sources agree on:
- February 15, 2026 (JST): Advantest detected unusual activity in its IT environment, started incident response and isolated affected systems, according to its original notice as reported by DailySecu and Almeida Law Group.
- February 19, 2026 (JST): Advantest disclosed the incident publicly. It said an unauthorized party may have accessed parts of its network and deployed ransomware. At that point it could not confirm whether customer or employee data was affected, and it promised to notify individuals if it found evidence of compromise (BleepingComputer, DailySecu).
- October 5, 2026: Advantest America, Inc. appeared in breach report summaries from the Vermont and California Attorneys General (Almeida Law Group, Cole & Van Note, DataBreachRights).
- October 6, 2026: Advantest Corporation dated its individual notification letters, which confirm that data was taken (primary notice).
One unresolved point is when the intrusion started. The company's letter says only that it "became aware" of the incident in February 2026. Cole & Van Note, a plaintiff firm, says individuals were told their data "had been accessed on January 23, 2026," which would put initial access about three weeks before detection. Neither the company letter nor BleepingComputer supports that date, so treat it as unverified until Advantest or a regulator filing confirms it. A dwell time of several weeks before detection would still match typical ransomware intrusions.
The company letter says Advantest worked with "leading cybersecurity firms and relevant authorities, including law enforcement agencies." It also says it took "potentially affected systems and additional systems offline" and put enhanced controls in place.
The notifications went out about seven and a half months after detection. DailySecu noted in February that confirming data theft and identifying affected individuals often takes much longer than recovering encrypted systems.
What Was Taken
Volume: not disclosed. Advantest has given no total, and BleepingComputer's question about it was not answered. The only figures come from Cole & Van Note, which cites 8 Vermont residents and more than 500 California residents. The California AG publishes breach notices only when more than 500 state residents are affected, so the CA posting is at least consistent with that floor. Neither number is a global total. Migliaccio & Rathod and DataBreachRights both describe the number affected as unknown.
Data types: accounts differ by source.
- Primary (company letter): The California AG sample letter is a mail-merge template. The only data field still visible in it is Driver's License, and the other fields are placeholders. The real data types probably vary from one recipient to the next.
- Regulator summaries, as reported by law firms: Almeida Law Group and Cole & Van Note say the Vermont AG filing for Advantest America lists Social Security numbers, financial account information, and credit/debit card information. DataBreachRights describes full names, SSNs and other identifying information.
- Broader claims (single OTHER source): Migliaccio & Rathod say the exposed data "may include" SSNs, medical information, financial information, contact details, dates of birth, driver's license numbers and passport numbers. No primary or outlet source we reviewed confirms the medical or passport categories, so treat them as unconfirmed.
Whose data: BleepingComputer says it is unclear whether the data belongs to customers, employees, partners, or a mix. The filings come from the US subsidiary and include SSNs and financial account data, which points toward employee or HR and payroll records. That is our inference, not a company statement.
Advantest says it has "no information suggesting that your PII has been disclosed publicly or otherwise misused." It is offering 18 months of Kroll identity, credit and web monitoring, with enrollment open until January 4, 2027.
Why It Matters
- Semiconductor supply-chain exposure. Advantest is a major ATE supplier. Almeida Law Group says chipmakers including Intel, Samsung and TSMC use its systems. DailySecu pointed out that test equipment vendors connect to customer fabs through remote maintenance and partner links, so an intrusion at one of them is a supply-chain concern even when only personal data is confirmed stolen. None of the sources reports any production disruption or impact on customer environments.
- "No data theft confirmed" is a provisional statement. In February, Advantest said it could not determine whether data had been affected. Eight months later, theft is confirmed. Defenders and third-party risk teams should treat early ransomware disclosures that report no confirmed exfiltration as incomplete.
- Japanese manufacturers remain under pressure. DailySecu places this incident in a run of attacks on Japanese manufacturing, retail, hospitality and telecom companies in 2026.
- Litigation follows quickly. At least three US plaintiff firms opened investigations within a day of the regulator postings. Companies with US subsidiaries should expect that US state notification laws will make the breach public and draw class-action interest, wherever the parent company is based.
- Product security and corporate IT are separate. Advantest's compliance page describes a Product Security Incident Response Team (PSIRT) formed in FY2026, with a secure-by-design policy for its products. That program covers vulnerabilities in Advantest products. It is not evidence about how the company's corporate IT network was breached, and nothing in the sources links the two.
The Attack Technique
Unknown. Advantest has not said how the attackers got in, and none of the eight sources identifies the initial access vector, the ransomware family or the operator. DailySecu and Almeida Law Group both report that no ransomware group had claimed the attack as of February and March 2026, and none of the October sources mentions a claim.
What the sources do establish:
- The attackers had network access to "parts of" the environment and deployed a ransomware payload (company disclosure via BleepingComputer and DailySecu).
- Data was taken from servers before or during the attack, which is a double-extortion pattern (company letter).
- If Cole & Van Note's January 23 access date is correct, the attackers were inside for about three weeks before detection. This is unverified.
The lack of a leak-site claim, eight months on, could mean a ransom was paid, an operator chose not to publish, or a group that does not run a public leak site. The sources do not support picking any one of these.
What Organizations Should Do
- Assess third-party exposure now. If you are an Advantest customer, partner or supplier, ask the company directly whether your contacts, support data or remote-maintenance credentials were in scope. Review and rotate any shared credentials or vendor remote-access paths into fab or test environments.
- Hunt for long dwell times. The intrusion may have started weeks before detection, so keep 90+ days of authentication, VPN and EDR telemetry. Hunt for staging and exfiltration activity, such as archive creation and large outbound transfers to cloud storage, not only for encryption.
- Segment HR and payroll data stores. SSNs and financial account data appear to be in scope. Isolate HRIS, payroll and benefits systems from general IT, enforce least-privilege access, and alert on bulk reads or exports.
- Plan disclosures as interim findings. Early notices should say "no evidence yet" rather than "no impact," and should include a commitment to update. Map US state AG notification requirements for every subsidiary ahead of time so regulator postings do not come out before your own communication.
- Advise affected individuals. People who received a letter should enroll in the Kroll monitoring before January 4, 2027. They should also consider a credit freeze with all three US bureaus, set fraud alerts, and watch for phishing that uses the breach as a lure.
- Harden remote access for OT and test-equipment vendors. Require MFA, just-in-time access and session recording for all vendor remote-maintenance connections, and log them separately from corporate IT so that a compromise on the vendor side cannot move straight into production environments.
Sources: Advantest confirms personal information stolen in ransomware attack | Advantest Corporation - Notice of Data Breach | Advantest America, Inc. Data Breach Investigation Almeida Law Group | 日 반도체 검사장비 핵심기업 어드반테스트, 랜섬웨어 공격 정황 확인…고객·임직원 정보 영향 여부 조사 중 < 해외 < 이... | Advantest Data Breach Investigation - Cole & Van Note - California... | Advantest Corporation Data Breach Investigation - M&R | Advantest America Data Breach Exposes SSNs | Product Security|Compliance