# Advantest Discloses Data Breach Months After February 2026 Ransomware Attack

> Japanese semiconductor test-equipment maker Advantest confirmed in October 2026 that attackers extracted personal data from its servers during the ransomware attack first disclosed on 19 February 2026. Exposed data includes names, dates of birth, contact details, SSNs, passport and driver's license numbers, and medical and financial information; no ransomware group has claimed the attack.

- **Published:** 2026-10-10T00:00:00Z
- **Last reviewed:** 2026-10-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3231
- **ID:** TL-2026-3231
- **Severity:** MEDIUM
- **Category:** DATA_BREACH
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 11 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Advantest Corporation (Tokyo; automatic test equipment for chipmakers, roughly 7,600 employees) detected unusual activity in its IT environment on 15 February 2026 (JST) and on 19 February 2026 publicly stated it was responding to a cybersecurity incident involving ransomware. Preliminary findings indicated that an unauthorized third party may have gained access to portions of the company's network and deployed ransomware. The company activated incident response, isolated affected systems and engaged third-party cybersecurity experts. At that time it reported no compromise of personal or corporate data and warned that facts could change.

In early October 2026 Advantest began notifying individuals that the threat actor had accessed its systems and extracted some data from its servers. Agency notifications were dated 5 October 2026 and consumer letters 6 October 2026. Notices filed with the California Attorney General state that more than 500 California residents are affected; Massachusetts lists 14 and Vermont 8. The company has not disclosed a total count, nor whether affected people are customers, employees, partners or a mix. A breach-notification aggregator (ClaimDepot) lists the breach date as 23 January 2026 and names Advantest America Inc. and its parent as the affected entities; this conflicts with the 15 February detection date in company and press statements and is unverified.

Exposed data categories are contact information, dates of birth, Social Security numbers, national ID numbers, driver's license numbers, passport numbers, medical information, financial information, financial account / credit and debit card information and other ID numbers. Advantest says it has no information that the data has been leaked or misused, and is offering 18 months of Kroll credit and web monitoring with an enrollment deadline of 4 January 2027.

The ransomware family, the initial access vector, the dwell time and the actor are not disclosed in any source reviewed, and no ransomware leak-site claim was found. No CVEs, malware hashes, IPs or domains have been published, so no BeaconBeagle correlation was possible. General reporting (Dragos via Help Net Security) notes that Akira, Qilin and Play are prominent groups targeting manufacturers and that over half of industrial ransomware incidents involve double extortion; this is sector context only and is not an attribution of this incident. The MITRE mapping below is limited to behaviors stated in sources (ransomware deployment, data extraction from servers) plus the unauthorized-access precondition, with the access method left generic.

## MITRE ATT&CK

- T1078 Valid Accounts
- T1005 Data from Local System
- T1657 Financial Theft

## Sources

- [Advantest Discloses Data Breach Months After Ransomware Attack (SecurityWeek)](https://www.securityweek.com/advantest-discloses-data-breach-months-after-ransomware-attack/)
- [Advantest confirms personal information stolen in ransomware attack (BleepingComputer)](https://www.bleepingcomputer.com/news/security/advantest-confirms-personal-information-stolen-in-ransomware-attack/)
- [Advantest Responds to Cybersecurity Incident (Advantest press release)](https://www.advantest.com/en/news/2026/20260219.html)
- [Japanese chip-testing toolmaker Advantest suffers ransomware attack (Help Net Security)](https://www.helpnetsecurity.com/2026/02/23/advantest-suffers-ransomware-attack)
- [Global Chip Supplier Advantest Discloses Cyber Incident (eSecurityPlanet)](https://www.esecurityplanet.com/threats/global-chip-supplier-advantest-discloses-cyber-incident/)
- [Advantest Data Breach Exposes Medical Information and Contact Details (ClaimDepot)](https://www.claimdepot.com/data-breach/advantest-2026)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3231
