"In February 2026, Advantest became aware of a cybersecurity incident in which an unauthorized third party accessed Advantest systems and extracted some data from our servers," reads the company's notification.
Advantest statement on the February 15 intrusion
Advantest Corporation, a Japanese global manufacturer of automated test equipment for the semiconductor industry, disclosed that on February 15 a threat actor breached its network and gained access to parts of its systems. At the time of the initial disclosure, the company reported that a ransomware payload had been deployed but said it could not determine whether customer or employee data had been impacted. In a follow-up notification dated October 6, 2026, Advantest confirmed that personally identifiable information (PII) had been extracted from its servers.
Data types the intruder extracted
The October notification lists the categories of PII that were taken. According to Advantest, the compromised data includes:
- Contact information
- Date of birth
- Social Security Number (SSN)
- National ID number
- Driver’s license
- Passport number
- Medical information
- Financial information
- Other ID numbers
The company did not specify whether the records belong to customers, employees, partners, or some combination of those groups.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildCompany actions: notification, monitoring, and guidance
Advantest is notifying affected individuals and offering mitigation services. The firm is providing instructions to enroll in free 18-month identity theft, credit, and web monitoring services through Kroll, with a deadline of January 4, 2027, for letter recipients to activate the offer. The company also states that it has no information indicating the compromised data has been leaked or otherwise misused, while acknowledging the elevated risk of identity theft and fraud for those whose information was exposed.
In its notification, Advantest recommends that impacted individuals closely monitor accounts and financial statements for suspicious activity and report unknown transactions to their banks. The company also warns recipients to be cautious about phishing attempts: avoid clicking links or opening attachments, and do not send money or share sensitive information in response to requests via email or text.
Public claims, outreach, and unanswered operational questions
BleepingComputer contacted Advantest with questions about the number of affected individuals but had not received a response as of publication. At the time of writing, BleepingComputer could not find any public claims from ransomware groups asserting responsibility for the attack. Beyond Advantest’s confirmations of access and data extraction, the company has not released detailed operational specifics about which systems were affected or how the extraction was performed.
What this means for customers, employees, and partners
- Customers: Those who receive notification letters will have a defined mitigation offer to enroll in 18 months of Kroll monitoring; they should consider activating the service before the January 4, 2027 deadline and closely review financial and account statements.
- Employees: Any staff named in the extracted datasets face increased identity-theft risk and are likewise advised to enroll in the monitoring service and to be vigilant for targeted phishing or social-engineering attempts.
- Partners: Vendors and business partners should assume the possibility of exposed contact and identity records and examine their own contracts and incident-response expectations with Advantest, while monitoring for suspicious communications that reference the breach.
Advantest’s October confirmation closes one part of the timeline—establishing that PII was taken—but leaves other concrete questions open, most notably the number of people affected and whether the data has been shared or posted elsewhere. For now, the company has emphasized remediation through monitoring services and warned of the heightened risk of identity theft and fraud. Recipients of the company’s notification have until January 4, 2027, to accept the monitoring offer; beyond that date, the notification sets a clear, time‑bound path for the initial mitigation step.
Source: BleepingComputer — Advantest confirms personal information stolen in ransomware attack




