Advantest’s letter dated Oct. 6, 2026 finally answers the question the Japanese chip-testing equipment maker left open in February: yes, data left its servers. The company wrote that in February 2026 it “became aware of a cybersecurity incident in which an unauthorized third party accessed Advantest systems and extracted some data.” The letters carry a deadline of Jan. 4, 2027 for the 18 months of Kroll identity protection on offer.
Advantest has not disclosed how many people received the letter or whether they are customers, employees or partners.
From a January Date to an October Letter
Advantest first went public on Feb. 19, 2026, saying it had detected unusual activity in its IT environment on Feb. 15, isolated affected systems and hired outside cybersecurity experts. Its statement said preliminary findings suggested an unauthorized third party may have gained access to portions of the network and deployed ransomware, and that it would notify customers or employees directly if their data proved to be affected. Nothing in that statement confirmed theft, and it said the investigation was ongoing, with regular updates promised on the company’s news page.
The California Attorney General’s breach database now carries an entry for Advantest America, Inc. that lists a breach date of Friday, Jan. 23, 2026, three weeks before the detection date in Advantest’s own announcement, and attaches the individual notice letter. The entry does not explain the gap between the two dates, and the letter itself says the company became aware of the incident in February.
Nine Categories of Data, From Passport Numbers to Medical Details
The template letter lists what may be involved: contact information, date of birth, Social Security number, national ID number, driver’s license, passport number, medical information, financial information and an “other ID number.” Because the posted copy is a template with placeholders for name, address and membership number, it cannot show which of the nine categories reached any individual. The letter does not say which categories apply to whom.
The letter says Advantest has no information that the data has been publicly disclosed or misused, while acknowledging that the incident may raise the recipient’s risk of identity theft or fraud. It adds that the company took affected systems offline, added security measures and notified law enforcement and international authorities. The signatory is “Advantest Corporation,” with no individual named.
BleepingComputer reported the letter’s contents and noted that no ransomware group had publicly claimed the attack as of its Oct. 7 article, and that Advantest had not answered its questions about the number of people affected. Its report, by Bill Toulas, connects the confirmed theft to the ransomware intrusion Advantest disclosed in February.
Kroll’s 18 Months and the January 4 Cutoff
The package Advantest is offering through Kroll runs 18 months and has three parts: single-bureau alerts on the recipient’s credit file, unlimited consultation with a Kroll fraud specialist, and identity-theft restoration handled by a dedicated Kroll investigator. Enrollment requires the activation link and membership number printed in each letter. Eligibility is limited to people over 18 with established U.S. credit, a Social Security number in their own name and a U.S. residential address.
Those conditions matter for a company whose customers and staff are global. A recipient abroad, a minor, or an adult with no U.S. credit file would not qualify for the Kroll package even though the letter’s data list includes passport and national ID numbers that apply to people everywhere. The letter does not describe any alternative offer for them. Advantest’s support center takes questions at +1 (844) 301-0189 on weekdays, in U.S. Central business hours. The letter also lists the three credit bureaus, the FTC’s identity-theft line and annualcreditreport.com, and points to Kroll’s program site, info.krollmonitoring.com, for details of the three services.
A Supplier With No Public Headcount
Advantest, a Tokyo-based maker of semiconductor test equipment with about 7,600 employees according to BleepingComputer’s February report. SecurityWeek noted in February that its customers reportedly include Intel, Samsung and TSMC, and that other chipmakers, among them Nexperia, TSMC, Microchip Technology and Foxsemicon, had recently been hit by ransomware as well.
BleepingComputer reports that the notification letter is posted on the California Attorney General’s website, which is how the Oct. 6 date and the Jan. 4 activation deadline became public. The company also recommends that recipients watch account statements, report unknown transactions to their bank and treat unsolicited emails and texts asking for money or sensitive information as phishing.
SecurityWeek observed in February that no known ransomware group had claimed the attack and suggested the operators might still seek a ransom before posting stolen data on a leak site. As of BleepingComputer’s Oct. 7 article, the picture had not changed: no public claim from any group, and no response from Advantest to questions about the number of people affected.
The record as of Oct. 7 therefore holds a template letter, a Jan. 4, 2027 activation cutoff, and a California entry dated Jan. 23, with no count of victims.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Lake Powell sank to a record 3,517 feet, nearing the level that stops Glen Canyon Dam’s turbines
- Seven of Earth’s nine planetary boundaries are breached, and all seven are worsening
- The NSA says three phone features should be off whenever you aren’t using them
- Hurricane Hunter radar shows four warning signs that a tropical cyclone is about to strengthen, a University of Miami study found