Advantest Confirms Personal Data Extraction
Advantest’s 6 October notice says attackers extracted data, including the recipient’s personal information, during its February ransomware incident. It does not describe a new October attack or give an affected total.
The October letter resolves the earlier uncertainty
California records 23 January as the known breach date. Advantest says it detected unusual activity on 15 February, Japan time. Its March update still treated data access or removal as under investigation; the October letter confirms extraction.
These dates answer different questions: regulator-known event, company detection, publication and recipient notification. They should not be merged into one timestamp.
The field list is personalised
The personalised field can include contact details, date of birth, Social Security or other government IDs, medical information and financial information. The public sample is a template, so the list does not apply to every recipient.
Advantest says it had no information at notice time suggesting public disclosure or misuse. That is a time-bound company statement, not proof that misuse cannot occur or will not later be found.
Choose protection from your own letter
The letter offers 18 months of Kroll credit and web monitoring, with enrolment required by 4 January 2027. Verify the sender through an official Advantest channel, then use the membership details in your own notice rather than information forwarded by someone else.
If your notice identifies a Social Security number or financial information, consider placing a free security freeze with each major credit bureau. A monitoring alert can show later activity, while a freeze is designed to make new credit harder to open without your consent.
Review financial, credit and medical statements for activity you do not recognise. Use unique passwords and two-step verification, but do not interpret that precaution as evidence that passwords were extracted. Preserve the notice and suspicious follow-up messages.
Copied identity data can remain useful after access has been closed. BlackTree’s Hasbro analysis explains why closing an account does not recover identity records that have already left an organisation. That comparison supports protective action, not a claim of a shared attacker or technique.
Sources: Advantest’s 19 February statement and 4 March update; the California attorney general’s SB24-630848 filing and individual notice.


