Advantest Corporation reported a cybersecurity incident in which an unauthorized party appears to have accessed parts of its network and deployed ransomware, impacting certain internal systems. The company said it detected unusual activity on Feb. 15 (JST), activated incident response procedures, isolated affected systems, and engaged third-party cybersecurity specialists to support investigation and containment; the investigation remains ongoing and findings may change as more facts are confirmed.
Public reporting echoed Advantest’s statement that the scope and responsible ransomware group are not yet identified, and noted the broader trend of increased ransomware targeting of industrial and manufacturing organizations, including the semiconductor sector. Advantest stated it will provide updates and, if the investigation determines customer or employee data was affected, it will notify impacted individuals directly with guidance on protective measures.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
By February 20, 2026, Advantest said it was continuing its investigation into the incident while assessing potential operational disruption and financial impact. At that time, no threat group had been publicly identified or claimed responsibility.
On February 19, 2026, Advantest publicly confirmed it was responding to a cybersecurity incident affecting parts of its internal network. The company said it would notify impacted individuals directly and provide guidance if customer or employee data exposure is confirmed.
Advantest's preliminary investigation found that an unauthorized third party had accessed parts of its network and may have deployed ransomware. The initial access vector, full scope of the intrusion, and whether data was stolen remained under investigation.
On February 15, 2026, Advantest detected unusual activity in its IT environment and activated incident response procedures. The company isolated affected systems and engaged third-party cybersecurity experts to help contain and investigate the incident.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourceadvantest.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.