Advantest, the Japanese semiconductor test-equipment maker, has confirmed that the February ransomware attack stole personal data. The notice is dated 6 October, almost eight months after the intrusion.
What happened
On 15 February 2026 an unauthorized party accessed Advantest systems, deployed ransomware, and extracted data. At the time the company could not say whether personal data was included. The new notice says it was.
Exposed fields can include contact details, date of birth, Social Security numbers, national ID numbers, driver's licenses, passport numbers, medical information, and financial information. Advantest says it has no information that the data has been misused. BleepingComputer could not find a public ransomware claim and did not get a victim count.
Who is affected
Letter recipients, not the general public. Advantest has not said whether those people are employees, partners, customers, or a mix. Anyone in a semiconductor supply chain who exchanged identity documents with Advantest should watch for a notice.
- Identity documents and government ID numbers
- Medical and financial information
- Free Kroll monitoring for 18 months, enrollment open until 4 January 2027
What to do now
If a notice arrives, enroll in the monitoring offer and treat unexpected calls or invoices that cite Advantest as suspicious.
For suppliers and MSPs, the lesson is the lag. A ransomware event in February can still become a personal-data notification in October. Keep the incident file open until the data-mapping answer is written down.
Source: BleepingComputer, Advantest confirms personal information stolen in ransomware attack.
Also on the blog
- CVE-2026-21589: unauthenticated file read on 8 Atlassian products
- CVE-2026-88779 crashes SAML NetScaler, patch by 7 October
- CVE-2026-102255: CVSS 10 SSRF in SonicWall SMA1000
- PoeLLM malware hits 2,100 exposed AI servers
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.