Advantest Confirms Personal Data Stolen in Ransomware Attack

Advantest has confirmed its February ransomware attack resulted in data theft involving potentially sensitive identity, medical and financial information.
Adventest logo overtop red abstract background.

Japanese semiconductor testing giant Advantest has confirmed that attackers stole personal information from its servers during a ransomware attack disclosed nearly 8 months ago, with exposed data potentially including Social Security numbers, identification documents, medical information and financial records.

The confirmation comes in breach notification letters dated Oct. 6, significantly expanding what was publicly known about the February incident. Advantest initially confirmed that ransomware had been deployed inside its network but said it was still investigating whether customer or employee information had been accessed or exfiltrated.

The company now says an unauthorized third party extracted data from its servers and that personally identifiable information belonging to notification recipients was among the stolen material.

Stolen data includes sensitive identity information

Advantest’s breach notification lists a wide range of information that may have been affected, depending on the individual.

The potentially compromised information includes contact details, dates of birth, Social Security numbers, national identification numbers, driver’s license information, passport numbers, medical information, financial information and other identification numbers.

Not every affected person necessarily had every category of information exposed. The notification is structured to identify the specific types of data affected for each recipient.

Advantest said it has no information indicating that the stolen personal information has been publicly disclosed or otherwise misused.

However, the company acknowledged that the breach may place affected individuals at increased risk of identity theft or fraud.

The total number of people affected remains unclear.

A filing with the California Attorney General indicates that the notification was sent to more than 500 California residents, the threshold that requires organizations to submit a sample breach notice to the state. Separate regulatory filings indicate additional individuals were affected in other states.

February attack initially left data theft uncertain

Advantest first disclosed the ransomware incident on Feb. 19, 4 days after detecting unusual activity in its IT environment.

The company said an unauthorized third party appeared to have gained access to portions of its network and deployed ransomware.

Advantest activated its incident response procedures, isolated affected systems and brought in outside cybersecurity specialists to investigate and contain the attack.

At that stage, the company had not determined whether customer or employee information had been compromised. It said affected individuals would be notified if the investigation established that their data had been impacted.

An update published March 4 showed that the investigation was still focused on that question.

Advantest said external cybersecurity specialists no longer saw evidence of unauthorized parties remaining in its environment, but investigators were continuing to determine what information may have been accessed or exfiltrated.

The company also said at the time that it had found no indication that data connected to the incident had been publicly released.

The Oct. 6 notifications now resolve one of the most important unanswered questions from that investigation: data was taken from Advantest’s servers.

Attack temporarily affected company systems

The February ransomware attack also forced Advantest to isolate potentially affected systems and proactively take additional systems offline while investigators worked to contain the intrusion.

That created what the company described as operational challenges for some customers, partners and suppliers. Advantest implemented workarounds while restoring affected systems.

By March, the company said it did not expect the incident to have a material impact on its financial results for the fiscal year ending March 2026.

Advantest has since said it is strengthening its broader cybersecurity framework based partly on lessons learned from the attack.

The company’s security initiatives include improvements involving network security, identity and access management, endpoint protection, cloud and application security, and security operations.

Breach reaches a major semiconductor supplier

The incident is notable because of Advantest’s position in the global semiconductor supply chain.

Headquartered in Tokyo, Advantest develops automated test equipment and related systems used to test semiconductors and electronic components during development and mass production.

The company says tens of thousands of semiconductor test systems operate on production lines worldwide and that more than 90% of its sales in recent years have come from outside Japan.

Advantest reported holding approximately 58% of the global semiconductor tester market in 2024, underscoring the company’s role in an industry increasingly important to AI infrastructure, data centers, consumer electronics and other technology sectors.

There is currently no indication that the ransomware attack compromised Advantest products or semiconductor equipment deployed at customer facilities. The confirmed exposure concerns information extracted from the company’s servers.

Affected individuals offered monitoring

Advantest is offering affected individuals 18 months of complimentary credit and web monitoring services through Kroll.

Because the stolen information can include government-issued identifiers, financial information and medical information, some recipients face risks that extend beyond conventional phishing.

Social Security numbers and other identification data can potentially be used for identity theft, fraudulent account creation and impersonation. Contact information combined with other personal details can also make phishing attempts more convincing.

The company recommends that affected individuals remain alert for suspicious activity and review financial account statements and credit reports for unauthorized transactions or accounts.

No ransomware group has publicly been confirmed as responsible for the attack, and Advantest has not attributed the intrusion to a specific threat actor.

The company also has not disclosed whether it received a ransom demand, whether negotiations took place or whether any payment was made.

For Advantest, the Oct. 6 notification marks an important change in the incident’s confirmed scope. What began in February as a ransomware attack with uncertain data impact is now a confirmed breach involving the theft of potentially highly sensitive personal information.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site →