Japanese Chip Tester Advantest Hit by Ransomware

A major supplier to Intel, Samsung, and TSMC faces a cybersecurity incident that highlights semiconductor supply chain vulnerability.

Illustration: Japanese Chip Tester Advantest Hit by Ransomware
AI-generated illustration · Sylvaris

What happened

<cite index="56-4,56-5">Advantest detected unusual activity in its IT environment on February 15, 2026, and immediately activated incident response protocols, isolated affected systems, and engaged third-party cybersecurity experts</cite>. <cite index="57-3,57-4,57-5">The Japanese company makes automatic test equipment for the semiconductor industry and serves major chipmakers including Intel, Samsung, and TSMC</cite>.

<cite index="56-6">Preliminary findings indicate that an unauthorized third party may have gained access to portions of the company's network and deployed ransomware</cite>. <cite index="64-2">The company disclosed the incident on February 19, 2026</cite>.

Impact and scope unknown

<cite index="57-9,57-18">It remains unclear if the attackers exfiltrated any sensitive information from the company</cite>. <cite index="64-5">Tokyo-based Advantest employs 7,600 people, has annual revenue of more than $5 billion, and a market capitalization of $120 billion</cite>.

<cite index="57-22,57-23">No known ransomware group appears to have taken credit for the attack, though given that the intrusion was detected less than one week ago, the threat actor may still be hoping to obtain a ransom before posting it on a leak website</cite>.

Semiconductor industry under pressure

<cite index="57-24,57-25">It's not uncommon for threat actors to target the semiconductor industry, with major companies including Nexperia, TSMC, Microchip Technology, and Foxsemicon confirming ransomware hits in recent years</cite>. <cite index="57-26">The attack came just months after the Japanese government issued new operational technology security guidance for semiconductor factories</cite>.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.