Yaamlabs

Ransomware

Advantest confirms data theft 233 days after ransomware

Advantest's October 6 letters confirm SSNs, passports and medical data were stolen in its February ransomware attack. What recipients and IR teams should do.

Advantest, the Japanese maker of semiconductor test equipment, has started sending breach letters dated October 6, 2026 confirming that its February ransomware attack included data theft. The letters say an unauthorized third party "extracted some data from our servers", and list contact details, dates of birth, Social Security numbers (SSNs), national ID, driver's licence and passport numbers, medical information and financial information. Each letter is personalised, so a given recipient may have had only some of those fields exposed.

Filings show more than 500 affected California residents, 14 in Massachusetts and 8 in Vermont. Advantest has not given a total, and it is not clear whether the people are employees, customers, partners or a mix. No ransomware group has claimed the attack. Advantest detected the intrusion on February 15, so 233 days passed before the individual letters were dated. If you have worked with Advantest in the US, check your mail for one of these letters.

What happened, by date

On February 19, Advantest said it had detected unusual activity in its IT environment on February 15 (Japan time), isolated the affected systems and called in outside specialists. Early findings pointed to an unauthorized party getting into parts of the network and deploying ransomware. At the time it could not say whether customer or employee data had been taken, and promised to notify people if that changed.

The California Attorney General's breach list records the case under Advantest America, Inc. with a breach date of January 23, 2026 and a reported date of October 5, 2026. If that date marks first access, the attacker was inside for about three weeks before detection. Advantest's letter says only that it "became aware" of the incident in February, so treat the January date as the filing's figure rather than a confirmed account of initial access.

The letter says the incident was contained, the network was restored, and that it notified international authorities, including law enforcement. It says Advantest has no information that the data was published or misused. With no group claiming the attack and no leak site listing, there is no public sign of what the attacker did with the data or whether a ransom was discussed.

Why notification took eight months

Ransomware cases that involve theft follow two clocks. The first is technical: find how the attacker got in, contain them and restore systems. The second starts only when the company knows which records left the network and whose they were. The letter describes that second step as "a detailed assessment of the data in scope", and that review is usually what takes months.

Answering "whose data was taken" needs three things many companies do not have ready. One is egress evidence: firewall, proxy or cloud storage logs that show which hosts sent data out, how much, and when. Another is a file listing, ideally the exact paths the attacker staged or archived, recovered from the compromised hosts. The third is a data map that says which file shares and databases hold HR, payroll, benefits or customer identity records. Without those, the review team ends up scanning terabytes of mixed files for SSNs and passport numbers, then matching each hit to a person and a mailing address.

State law does not wait for a perfect answer. California's SB 446, in force since January 1, 2026, requires notice to individuals within 30 calendar days of discovering a breach, and a sample letter to the Attorney General within 15 days of notifying more than 500 residents. It allows delay for law enforcement or to determine the scope of the breach and restore systems. Massachusetts requires notice "as soon as practicable and without unreasonable delay" and does not let a company hold off because it has not yet counted the affected residents. Vermont sets a 45-day ceiling for consumer notice and a preliminary notice to its Attorney General within 14 business days. The clocks generally run from when a company discovers that personal information was involved, and Advantest has not said when that was, so this is not evidence it missed a deadline.

What to do if you got a letter

Your SSN, passport number and date of birth will still be valid long after the 18 months of monitoring ends, so add steps that last longer.

  1. Enrol in the Kroll service before January 4, 2027, using only the address and membership number printed on your paper letter. Kroll's credit monitoring here covers a single credit bureau, and you must be over 18 with a US credit file and an SSN in your name.
  2. Place a free security freeze at Equifax, Experian and TransUnion. A freeze stops new credit from being opened in your name; monitoring only tells you after it happens. Lift it temporarily when you apply for credit yourself.
  3. If your letter lists your passport or driver's licence number, ask the issuing agency whether it will replace the document with a new number, and watch for accounts opened with it.
  4. If medical or financial information is listed, read every insurer explanation of benefits and bank statement for claims or transfers you did not make.
  5. Expect phishing that uses the breach as the hook. Messages claiming to be from Advantest or Kroll asking you to "verify" details or click to enrol are suspect; go through the letter's printed details instead.

What to change in your own incident response

For anyone planning a ransomware response, ask how long your team would need to produce a list of names and addresses from a set of stolen file shares, and what evidence it would use.

Start with a data inventory that names the systems holding SSNs, government ID numbers, health and payroll data, and the owner of each. Keep outbound traffic logs from firewalls, web proxies and cloud storage for at least 90 days, with byte counts per destination, because data can be copied out days or weeks before the ransomware runs. When responders find staging folders, archive tools such as 7-Zip or WinRAR, or sync tools such as rclone on a compromised host, they should image the host and keep the file lists before anyone rebuilds it; those lists turn a review of everything into a review of what was copied.

Finally, sign the data review, call centre and mailing contracts before an incident, and agree with counsel in advance which states need rolling or preliminary notices, so none of it has to be negotiated while the review is under way.

Our security operations team sets up the logging and retention that let you answer "what left the network", and our compliance and audit readiness work maps where personal data sits and who owns each system. Open the chat and Yaali, our AI agent, will pass your question to an engineer.


Sources: Advantest notice of data breach, California Attorney General copy, California Attorney General breach list, Advantest statement, February 19, 2026, BleepingComputer, SecurityWeek, Help Net Security, BleepingComputer, February 2026, National Law Review on California SB 446, Massachusetts Attorney General: report a data breach, Vermont Legislative Counsel memo on the Security Breach Notice Act.

Back to the blog, or read this post on the full site.