Japanese semiconductor test-equipment manufacturer Advantest confirmed that attackers stole personal information during the ransomware attack it disclosed in February 2026. An October 6 notification identified exposed data including contact details, birth dates, identity documents and government identification numbers, medical information, and financial information. State filings list more than 500 affected California residents, 14 Massachusetts residents, and eight Vermont residents, but the total number affected and whether they are employees, customers, partners, or a combination remain undisclosed.
Advantest said it has no information suggesting that the stolen data has been publicly disclosed or misused, and no known ransomware group had publicly claimed responsibility as of October 7. The exposed information nevertheless increases the risk of identity theft and fraud. The company is offering affected individuals 18 months of free identity-theft, credit, and web monitoring through Kroll; recipients should enroll and monitor financial accounts and credit reports for suspicious activity.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
In a notification dated October 6, 2026, Advantest confirmed theft of personal information, including contact details, birth dates, government identifiers, and medical and financial information. The company said it had no information indicating leakage or misuse and offered affected individuals 18 months of free identity theft, credit, and web monitoring through Kroll.
A threat actor breached Advantest's network on February 15, 2026, gaining access to some systems. The February attack involved ransomware deployment and the extraction of data from company servers.
Advantest disclosed the network breach and ransomware deployment in February 2026. At that time, the company was still determining whether sensitive customer or employee information had been affected or exfiltrated.
Advantest's state notifications identified more than 500 affected California residents, 14 Massachusetts residents, and eight Vermont residents. The company did not disclose the total number of affected individuals.
After discovering the incident, Advantest took potentially affected and additional systems offline, enhanced security and monitoring, and reported containing the incident and safely restoring its network. The company also notified appropriate international authorities, including law enforcement.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcesecurityweek.com
Open sourcebleepingcomputer.com
Open sourceoag.ca.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.