Security2 publishersAlso reported elsewhere2 min readPublished
Advantest confirms February ransomware attackers stole SSNs, passport and medical data
Advantest confirmed on October 6 that February's ransomware intruders stole Social Security and passport numbers along with medical and financial data. Its chip-industry customers and suppliers cannot yet tell whether their own staff are affected.
The Watch · Security desk

What happened
- Attackers deployed ransomware on Advantest's network in February, and at the time the company said it could not tell whether customer or employee data was affected.
- The stolen fields also include contact details, dates of birth, national ID and driver's license numbers, and other ID numbers.
- BleepingComputer asked Advantest how many people were affected and had received no reply by publication.
- Advantest is offering 18 months of free Kroll identity theft, credit and web monitoring to recipients who activate by January 4, 2027.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Contact details were taken along with ID numbers, so phishers who already hold a recipient's data can reach that person; the guidance says never to send money or information in reply to email or text requests.
- decision Recipients get 90 days from the notice date to enroll, so anyone who leaves the letter unread for three months loses the free Kroll coverage.
- constraint Advantest's statement that it has no information of leaks or misuse is the only public account of where the data went, and recipients cannot check it for themselves.
I'd rate the fraud risk as real for anyone who gets a letter. Advantest itself acknowledges that the people exposed face an elevated risk of identity theft and fraud [12]. Recipients are also told to watch their account and financial statements and to report unfamiliar transactions to their bank [13].
The notice settles what kind of incident this was. "In February 2026, Advantest became aware of a cybersecurity incident in which an unauthorized third party accessed Advantest systems and extracted some data from our servers," it reads [5]. The next line is addressed to the recipient: "The data extracted from our servers included PII (personally identifiable information) belonging to you" [14]. That confirmation came 233 days after the February 15 intrusion [17].
Advantest makes automated test equipment for the semiconductor industry [1]. Semiconductor companies that buy from or supply Advantest should now review the incident as a data-theft breach, because exfiltration is confirmed [4]. The letters go to the individuals whose PII was taken [14]. A supplier will learn that its own staff are involved only if those people report receiving one.
The notice calls the intruder only "an unauthorized third party" [5]. BleepingComputer found no ransomware group publicly claiming the attack as of its report [15]. On that record this is one intrusion at one company, with no link yet shown to a wider campaign.
What to watch
- A ransomware group posting Advantest data on a leak site would name the operator and test the company's statement that it has no information of misuse.
- An answer to BleepingComputer's question on the number of affected individuals would size the breach for the first time.
- A statement from Advantest that customer or partner employees are among those affected would make this a vendor-risk notification for the semiconductor companies it serves.