Yes—later state-notice reporting says personal information was extracted from Advantest America. That is a later development than the company’s February 19, 2026, ransomware disclosure, which said the investigation had not yet determined whether customer or employee data was affected. The state-specific reports do not establish that every Advantest customer or employee was affected, or that all recipients had the same information exposed.
What happened, and when did Advantest report stolen data?
| Date | What was reported |
|---|---|
| February 15, 2026 (Japan time) | Advantest said it detected unusual activity in its IT environment, activated response protocols, isolated affected systems, and engaged outside cybersecurity experts. Advantest’s February 19 statement described the incident as ransomware-related. |
| February 19, 2026 | The company said preliminary findings suggested an unauthorized third party may have accessed parts of its network and deployed ransomware. Whether customer or employee data was affected remained under investigation. It said it would notify impacted people if the investigation determined their data was affected. |
| March 4, 2026 | Advantest reported that production, shipments, and customer support remained operational. It said it was still investigating what data may have been accessed or exfiltrated, and that monitoring had not found an indication that incident data had been released publicly. The update named Palo Alto Networks Unit 42 among the experts assisting with investigation, containment, and remediation. Read the company’s March 4 update. |
| October 5, 2026 | Secondary breach reports attributed later notices to state filings and said personal information was extracted. A California-filing tracker said the filings did not state a total affected-person count; a separate report on a Vermont notice listed a notice-specific count of eight. These are later, state-specific reports—not a company-wide total. |
The March statement that no public release had been detected did not mean no information had been accessed or extracted. It described what the company and its experts had found at that time; later reporting attributed to state notices described personal information as extracted.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Security with Keys, Anti-Theft, Screw Styles | $10.49 | Buy on Amazon |
What personal information was reported as exposed?
California filing report
Incident Security Authority’s October 5, 2026, tracker, which attributes its account to California Attorney General filings, says personal information was extracted and lists dates of birth and Social Security numbers among the data types. It says the filings do not state how many people were affected. The underlying California notice was not directly available for verification, so this reporting should not be treated as a complete or definitive list of exposed fields.
Vermont notice report
GalaxyWarden Threat Research’s October 5, 2026, report, attributed to a Vermont Attorney General notification, lists Social Security numbers, financial account codes, and credit or debit account information. It reports eight affected people for that notice. That figure applies to the Vermont notice described in the report; it is not an incident-wide count.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problems#1 Best Overall
- With strict control and, high factors, can be used with peace of mind
- Works with most desktops, docking stations with built-in security locking slot hole
- Fine workmans ship make sure they are perfect to use
- Protect your computer and its valuable data with this computer
- metal, multi-layer plating color, do not fade, long-life
The available reports do not establish one uniform set of exposed information for all recipients. If you receive a notice, use the data categories in that specific notice to decide what steps apply to you.
How many people were affected?
A total affected-person count for the incident is not established in the available reporting. The California-filing tracker says its filings do not state a total. The Vermont report gives a count of eight for its notice only, which should not be presented as the total across all states or affected people.
What should you do if you receive an Advantest America notice?
- Verify the notice. If an unexpected email, letter, or call claims to be from Advantest America, confirm it through a contact route you find independently or already trust. Do not rely on links or phone numbers in an unsolicited message.
- Read the notice’s specific data list. The reports describe different categories in different state notices; do not assume a detail reported for another notice applies to yours.
- Contact your financial institution if account data is listed. Use the number on your card or official account materials to ask about appropriate protective steps.
- Consider a credit freeze if Social Security numbers are listed. U.S. credit bureaus offer free credit freezes. A freeze can restrict access to your credit file, but it does not prevent every form of identity misuse.
- Check any monitoring offer’s terms. Incident Security Authority reports an offer of 18 months of free credit and web monitoring through Kroll for affected people. The underlying notice and eligibility terms were not directly verified, so rely on the authentic notice to confirm whether you qualify and how to enroll.
The available sources do not report that exposed information has been used for fraud, and the reported monitoring offer does not guarantee reimbursement or resolution.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What did Advantest say about operations and its response?
In its March 4 update, Advantest said production, shipments, and customer support remained operational and that it was restoring systems in a controlled manner. It reported isolating potentially affected systems, taking additional systems offline as a precaution, notifying relevant authorities including law enforcement, and using workarounds for customers, partners, and suppliers.
Recommended Free Tools
The company also said it had strengthened monitoring, implemented enhanced security measures, and reinforced internal controls. These are actions reported by Advantest, not an independent assessment of their effectiveness. The March 4 statement is the latest company incident update identified in the sources cited here; it should not be read as a current operational assessment.
Is this the ransomware incident Advantest disclosed in February?
The later notice reporting concerns Advantest America and describes personal information as extracted in connection with the 2026 incident. Advantest’s February 19 statement was the initial public disclosure of a ransomware-related incident; its March 4 update said the data-impact investigation was continuing. The later reports add information about state notices, but they do not establish that every customer or employee was affected.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

