Japanese semiconductor-testing giant Advantest has confirmed that hackers stole personal information during a ransomware attack first disclosed in February 2026.
The company is now notifying affected individuals after completing a detailed review of data taken from its systems.
The stolen information may include names, dates of birth, contact details, Social Security numbers, national identification numbers, passport details, driver’s licence information, medical records and financial information.
Advantest said it currently has no evidence that the stolen information has been publicly released or misused.
However, the company acknowledged that affected individuals may face an increased risk of identity theft or fraud.
FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals
Attack Was First Detected in February
Advantest first disclosed the cybersecurity incident on February 19.
The company said it had detected unusual activity in its IT environment on February 15 and immediately activated its incident-response procedures.
Affected systems were isolated and external cybersecurity specialists were brought in to investigate the breach.
Advantest said at the time that an unauthorised third party appeared to have accessed parts of its network and deployed ransomware.
What remained unclear was whether customer, employee or other sensitive information had actually been stolen.
That question has now been answered.
The company’s latest notification confirms that attackers extracted data from Advantest servers during the incident.
Personal and Financial Data Was Taken
According to breach notifications filed with US state authorities, the stolen information varied depending on the individual affected.
It could include basic contact information and dates of birth.
In more serious cases, the exposed data may include Social Security numbers, national identification numbers, driver’s licence details and passport numbers.
Medical and financial information was also present in some of the stolen files.
That combination of information creates a higher risk than a breach involving only names or email addresses.
Identity documents and financial details can be used in impersonation attempts, fraudulent account applications and highly convincing phishing attacks.
Total Number of Victims Still Unknown
Advantest has not disclosed the total number of people affected globally.
Its filing with the California Attorney General indicates that more than 500 California residents were impacted.
Separate notifications filed in Massachusetts and Vermont list 14 and eight affected residents respectively.
Those figures do not represent the overall breach total.
They only reflect residents covered by specific state notification requirements.
The final number of affected employees, customers or other individuals therefore remains unknown.
Company Offers 18 Months of Monitoring
Advantest is offering affected individuals 18 months of complimentary credit and web monitoring services through Kroll.
The company has advised recipients to monitor financial accounts, credit reports and other sensitive services for suspicious activity.
Advantest said it has not seen evidence that the stolen personal information has been made public.
It also said there is currently no indication that the information has been misused.
The absence of known misuse does not eliminate the risk.
Stolen personal data can sometimes remain unused for months before appearing in fraud or identity-theft activity.
Core Business Operations Continued
The ransomware incident caused disruption to parts of Advantest’s internal IT environment.
However, the company said its main business operations remained functional.
Production, shipments and customer-support activities continued while additional systems were gradually restored.
Advantest said in March that its containment actions and business-continuity plans had limited the operational impact.
External cybersecurity experts later found no evidence that unauthorised parties remained inside the company’s environment.
Advantest Works With Major Chipmakers
Advantest is a major supplier of automatic test equipment used by semiconductor manufacturers.
Its technology is used to test chips and other electronic components before they are deployed in commercial products.
SecurityWeek reported that the company supplies equipment to large chipmakers including Intel and Samsung.
That makes the breach notable because companies involved in semiconductor supply chains often hold valuable technical, employee and business information.
There is currently no public indication that the attack disrupted semiconductor production or exposed customer intellectual property.
The newly confirmed breach relates specifically to personal information found in the stolen data.
No Ransomware Group Has Claimed Responsibility
No major ransomware group is known to have publicly claimed responsibility for the attack on Advantest.
That makes attribution difficult.
Ransomware groups frequently publish stolen company data on leak sites when victims refuse to pay.
In some incidents, however, attackers choose not to identify themselves publicly or do not publish the stolen material.
Advantest has also not disclosed whether it received a ransom demand or whether any payment was made.
There is no confirmed information identifying the attackers behind the February incident.
Investigation Lasted Several Months
The long gap between the February attack and the October breach notification reflects the complexity of determining exactly what data attackers accessed.
After containing a ransomware incident, companies often need to examine large volumes of files, server logs and backups.
They then have to identify which records contained personal information and determine which individuals need to be notified.
Advantest said in March that it was still investigating whether information had been accessed or exfiltrated.
The October notifications show that the data review ultimately confirmed that personal information had left company systems.
Ransomware Is Increasingly a Data-Theft Problem
Ransomware attacks were once mainly associated with encrypting files and demanding payment for restoration.
Modern ransomware operations increasingly focus on data theft as well.
Attackers may copy sensitive information before encrypting systems.
That gives them additional leverage because they can threaten to publish confidential information even if the victim restores operations from backups.
The Advantest incident follows that pattern.
The company was able to maintain its core operations, but the later confirmation of data theft created a second problem involving privacy, notification and identity-protection risks.
Semiconductor Companies Remain Attractive Targets
The semiconductor industry has become increasingly important to global economic and national-security policy.
Chipmakers and their suppliers operate complex international networks involving manufacturing, testing, design and logistics.
Cybercriminals may target these companies for employee information, intellectual property, financial records or access to larger supply-chain partners.
Advantest’s breach does not currently appear to have resulted in a major operational semiconductor disruption.
But it shows that companies supporting critical technology supply chains remain attractive ransomware targets.
What this means for you
Anyone notified by Advantest should treat the breach as an identity-theft risk rather than only a company IT incident. Monitor financial accounts and credit activity closely, and be especially cautious of calls or emails that use genuine personal information to appear legitimate.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics