Advantest confirms PII stolen in February ransomware attack
Advantest ransomware personal data notification

Advantest confirms PII stolen in February ransomware attack

Advantest, the Japanese semiconductor test-equipment maker, has confirmed that the February ransomware attack stole personal data. The notice is dated 6 October, almost eight months after the intrusion.

What happened

On 15 February 2026 an unauthorized party accessed Advantest systems, deployed ransomware, and extracted data. At the time the company could not say whether personal data was included. The new notice says it was.

Exposed fields can include contact details, date of birth, Social Security numbers, national ID numbers, driver's licenses, passport numbers, medical information, and financial information. Advantest says it has no information that the data has been misused. BleepingComputer could not find a public ransomware claim and did not get a victim count.

Who is affected

Letter recipients, not the general public. Advantest has not said whether those people are employees, partners, customers, or a mix. Anyone in a semiconductor supply chain who exchanged identity documents with Advantest should watch for a notice.

  • Identity documents and government ID numbers
  • Medical and financial information
  • Free Kroll monitoring for 18 months, enrollment open until 4 January 2027

What to do now

If a notice arrives, enroll in the monitoring offer and treat unexpected calls or invoices that cite Advantest as suspicious.

For suppliers and MSPs, the lesson is the lag. A ransomware event in February can still become a personal-data notification in October. Keep the incident file open until the data-mapping answer is written down.

Source: BleepingComputer, Advantest confirms personal information stolen in ransomware attack.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

PoeLLM malware hits 2,100 exposed AI servers
PoeLLM LiteLLM Ollama exposed AI cryptominer