Skip to content
RansomwareContained

Advantest confirms data stolen in February ransomware attack

Japanese semiconductor test-equipment maker Advantest began notifying individuals that a February 2026 ransomware intrusion had exfiltrated personal data, including Social Security and passport numbers.

Victim
Advantest

On 6 October 2026, Advantest β€” the Tokyo-based manufacturer of automated test equipment used across the global semiconductor industry β€” began notifying individuals that a ransomware intrusion earlier in the year had resulted in the theft of their personal data. The notice confirmed what the company had been unable to establish when it first disclosed the attack: that an unauthorized third party "extracted some data from our servers."

Advantest said it detected the breach on 15 February 2026, when an attacker gained access to some of its systems, and publicly acknowledged the ransomware incident days later. At the time, the company could not determine whether customer or employee data had been affected. The October notification resolves that question, though Advantest has not disclosed how many people were affected, nor whether they are customers, employees, business partners, or a combination.

What was exposed

According to the notice, the compromised information spans an unusually broad set of identity fields: contact details, date of birth, Social Security number, national ID number, driver's license number, passport number, and medical and financial information, among other identifiers. The breadth of the data β€” particularly passport and government ID numbers alongside medical and financial records β€” places affected individuals at elevated risk of identity theft and fraud.

No ransomware group has publicly claimed responsibility for the attack, and Advantest said it has no information indicating the stolen data has been leaked or misused. Even so, the confirmation that data left the company's servers makes this a materially more serious event than the operational disruption disclosed in February.

Response

Advantest said it is offering affected individuals 18 months of complimentary identity-theft, credit, and web monitoring through Kroll, with recipients given until 4 January 2027 to enroll. The company urged recipients to monitor their financial accounts, report any unrecognized transactions, and remain alert to phishing attempts that may follow a breach of this kind.

Timeline

  1. An unauthorized third party breaches Advantest's network and gains access to some systems.

  2. Advantest publicly discloses that it is responding to a ransomware attack affecting part of its network.

  3. Advantest begins notifying affected individuals that personal data was extracted during the intrusion.

Sources

  1. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/advantest-confirms-personal-information-stolen-in-ransomware-attack/
  2. securityweek.comhttps://www.securityweek.com/advantest-discloses-data-breach-months-after-ransomware-attack/

Related incidents

RansomwareContained

Foxconn Nitrogen ransomware breach (2026)

The Nitrogen ransomware group claimed on its dark-web leak site that it had stolen over 11 million files from Foxconn's North American facilities, including confidential information belonging to customers Apple, Dell, Google, Intel, Nvidia, and Sony. Foxconn said affected factories were resuming normal production.

Victim
Foxconn (Hon Hai Precision Industry)
Credential stuffingOngoing

FortiBleed: leaked dataset exposes VPN credentials for ~74,000 Fortinet firewalls

A dataset dubbed FortiBleed exposed valid Fortinet FortiGate VPN credentials β€” including plaintext passwords β€” for 73,932 firewall URLs across 194 countries, the product of a Russian-speaking crew that reused passwords from earlier breaches and infostealer logs rather than any new Fortinet vulnerability.

Victim
Organizations running Fortinet FortiGate firewalls worldwide