Threat reportData BreachTL-2026-3231
Advantest Discloses Data Breach Months After February 2026 Ransomware Attack
Advantest Discloses Data Breach Months After February 2026 (TL-2026-3231), also tracked as Advantest ransomware incident, is a medium-severity data breach, first published 2026-10-10. It has no confirmed attribution, affects Advantest Advantest Corporation corporate IT environment and servers, maps to 3 MITRE ATT&CK techniques (T1005, T1078, T1657), and is covered by 9 detection rules and 11 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 3MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 11Indicators of compromise
Key facts for TL-2026-3231
- Threat ID
- TL-2026-3231
- Also known as
- Advantest ransomware incident, Advantest cybersecurity incident
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- semi-conductors, manufacturing, technology
- Target regions
- japan, North America
- Detection rules
- 9
- Indicators of compromise
- 11
How Advantest Discloses Data Breach Months After February 2026 works
Japanese semiconductor test-equipment maker Advantest confirmed in October 2026 that attackers extracted personal data from its servers during the ransomware attack first disclosed on 19 February 2026. Exposed data includes names, dates of birth, contact details, SSNs, passport and driver's license numbers, and medical and financial information; no ransomware group has claimed the attack.
Advantest Corporation (Tokyo; automatic test equipment for chipmakers, roughly 7,600 employees) detected unusual activity in its IT environment on 15 February 2026 (JST) and on 19 February 2026 publicly stated it was responding to a cybersecurity incident involving ransomware. Preliminary findings indicated that an unauthorized third party may have gained access to portions of the company's network and deployed ransomware. The company activated incident response, isolated affected systems and engaged third-party cybersecurity experts. At that time it reported no compromise of personal or corporate data and warned that facts could change.
In early October 2026 Advantest began notifying individuals that the threat actor had accessed its systems and extracted some data from its servers. Agency notifications were dated 5 October 2026 and consumer letters 6 October 2026. Notices filed with the California Attorney General state that more than 500 California residents are affected; Massachusetts lists 14 and Vermont 8. The company has not disclosed a total count, nor whether affected people are customers, employees, partners or a mix. A breach-notification aggregator (ClaimDepot) lists the breach date as 23 January 2026 and names Advantest America Inc. and its parent as the affected entities; this conflicts with the 15 February detection date in company and press statements and is unverified.
Exposed data categories are contact information, dates of birth, Social Security numbers, national ID numbers, driver's license numbers, passport numbers, medical information, financial information, financial account / credit and debit card information and other ID numbers. Advantest says it has no information that the data has been leaked or misused, and is offering 18 months of Kroll credit and web monitoring with an enrollment deadline of 4 January 2027.
The ransomware family, the initial access vector, the dwell time and the actor are not disclosed in any source reviewed, and no ransomware leak-site claim was found. No CVEs, malware hashes, IPs or domains have been published, so no BeaconBeagle correlation was possible. General reporting (Dragos via Help Net Security) notes that Akira, Qilin and Play are prominent groups targeting manufacturers and that over half of industrial ransomware incidents involve double extortion; this is sector context only and is not an attribution of this incident. The MITRE mapping below is limited to behaviors stated in sources (ransomware deployment, data extraction from servers) plus the unauthorized-access precondition, with the access method left generic.
MITRE ATT&CK techniques used in TL-2026-3231
Collection
Initial Access
Impact
Affected products and versions in Advantest Discloses Data Breach Months After February 2026
- Advantest — Advantest Corporation corporate IT environment and servers holding personal information
- Advantest — Advantest America Inc.
Remediation for Advantest Discloses Data Breach Months After February 2026
Immediate actions
- Affected individuals: enroll in the Kroll credit and web monitoring offered by Advantest before 4 January 2027
- Place fraud alerts or credit freezes if SSN, passport or driver's license numbers were exposed
- Treat unsolicited contact referencing Advantest or the breach as potential phishing or social engineering
- Advantest customers and partners: review shared credentials, VPN and file-transfer connections with Advantest and rotate if in doubt
Longer-term hardening
- Segment networks and isolate servers holding personal data from general IT
- Deploy EDR with ransomware behavioral detection and monitor for bulk data staging and egress
- Maintain isolated, tested backups and rehearse the incident response plan
- Enforce MFA on remote access and privileged accounts
Timeline of Advantest Discloses Data Breach Months After February 2026
- Breach date listed as 23 January 2026 by breach-notification aggregator ClaimDepot (unverified; conflicts with company-stated 15 February detection)
- Advantest detects unusual activity in its IT environment (JST); BleepingComputer reports the network breach on this date
- Advantest publicly discloses a cybersecurity incident involving ransomware, states it isolated systems and engaged third-party experts, and reports no confirmed personal or corporate data compromise
- Help Net Security and eSecurityPlanet report the incident; no actor claim, no IOCs, no confirmed exfiltration at that time
- Breach reported to the California and Vermont Attorneys General (Massachusetts also notified): over 500 California, 14 Massachusetts and 8 Vermont residents affected
- Notification letters to affected individuals confirm threat actor extracted some data from Advantest servers; 18 months of Kroll monitoring offered
- SecurityWeek and BleepingComputer report the confirmed PII theft; no ransomware group has claimed responsibility
- Deadline for affected individuals to enroll in the Kroll credit and web monitoring services
Sources cited for Advantest Discloses Data Breach Months After February 2026
- Advantest Discloses Data Breach Months After Ransomware Attack (SecurityWeek)
- Advantest confirms personal information stolen in ransomware attack (BleepingComputer)
- Advantest Responds to Cybersecurity Incident (Advantest press release)
- Japanese chip-testing toolmaker Advantest suffers ransomware attack (Help Net Security)
- Global Chip Supplier Advantest Discloses Cyber Incident (eSecurityPlanet)
- Advantest Data Breach Exposes Medical Information and Contact Details (ClaimDepot)
Detection coverage for TL-2026-3231
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3231 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.