Advantest confirmed that hackers stole Social Security numbers and passport data in a ransomware attack that the company detected in February 2026. Public disclosure came in October. That gap, 233 days by the count in the source reporting, is the heart of the Advantest data breach disclosure delay, and it raises practical questions for anyone whose identity documents may have been in the stolen files.

This post walks through what is known, why the timing matters, and what you can do about it. It also addresses a common misconception: a VPN does not protect data that has already been taken from a company's servers.

What Advantest Disclosed and When

Advantest, a Japanese manufacturer of semiconductor test equipment, detected a ransomware attack in February 2026. According to the company's own statement dated February 19, 2026, it said that if its investigation determined customer or employee data was affected, it would notify impacted persons directly and provide guidance.

That notification came much later. Reporting on the filings indicates the notice letters are dated October 6, 2026, almost eight months after the attack was detected. The confirmed stolen data includes Social Security numbers and passport data. One of the sources we reviewed also notes a separate, earlier case in which Advantest delayed disclosure of a customer data breach for nearly three weeks, though we have no further details on that.

We do not have information in the source material on exactly how many people were affected, so we are not going to guess at a number.

Why 233 Days Matters for Stolen SSNs and Passports

A long gap between a breach and a notice does not necessarily mean the company was idle. Investigations into ransomware incidents can involve rebuilding systems, working out which files were copied, and then identifying whose records were in them. Still, the practical effect for the individual is the same: for months, people may not have known their most sensitive identifiers were in criminal hands.

Social Security numbers and passport data are different from a leaked password. You cannot easily change them. A password can be reset in minutes, but an SSN stays with you for life, and a passport number tied to your name and date of birth can support identity fraud for as long as the document is valid. That makes timing important in two ways:

  • Lost early-warning time. Fraud alerts and credit freezes work best when they are in place before someone tries to open an account in your name. Every month without notice is a month you could not take those steps on purpose.
  • Harder to trace. When misuse shows up long after the attack, it is harder to connect a fraudulent account to a specific breach.

This is also where a common question comes up. A VPN encrypts your traffic between your device and the VPN server and masks your IP address. It does nothing for records already sitting on an employer's or vendor's network. If attackers copied files from a company's systems, no consumer privacy tool changes that outcome. VPNs address a different risk, which is network-level surveillance and exposure on untrusted connections.

Which Disclosure Rules Apply and Where They Fall Short

The notice was filed with the California Attorney General's office, which publishes breach notices submitted under state law. In the United States, breach notification is governed largely by state laws rather than one national rule, and many of them require notice "without unreasonable delay" or within a set number of days, depending on the state. The exact requirements that applied to Advantest's notice are not spelled out in the source material, so we will not assert whether the company met or missed a specific legal deadline.

What can be said generally is where this kind of framework tends to be weak:

  • Vague timing language. Phrases like "without unreasonable delay" leave room for long investigations to count as reasonable.
  • Patchwork coverage. Because rules vary by state and country, people affected by the same incident can have different rights depending on where they live.
  • Notice goes to individuals, not always the public. Someone can be affected before any broad announcement reaches them.

Advantest is a Japan-based company with U.S. operations, so more than one regulatory regime may be relevant, but the source material does not detail that.

What This Means For You

If you received a letter from Advantest, treat it seriously and act on it now rather than waiting for signs of fraud. If you did not, the broader lesson still applies: organizations you deal with as an employee, customer, or job applicant may hold your SSN or passport details, and you often have little say over how well they are protected.

The key point is that your leverage lies in what you hand over and what you do after a notice arrives, not in tools that sit on your own connection.

Steps to Take If Your Identity Data Was Exposed

  1. Read the notice carefully. Note which data types are listed and any monitoring services offered.
  2. Place a fraud alert or credit freeze. A freeze restricts new credit being opened in your name. The company's notice also describes an extended fraud alert, which stays on your credit report for seven years.
  3. Review your credit reports. Check for accounts or inquiries you do not recognize.
  4. Watch for tax and benefits fraud. Stolen SSNs are commonly used to file false returns; consider an identity protection PIN if your tax authority offers one.
  5. Contact the passport issuer if needed. If you suspect your passport data is being misused, report it to the relevant authority.
  6. Be wary of follow-up scams. Breach news often triggers phishing that references the incident. Go to official sources directly rather than clicking links in unexpected messages.

Takeaways: Share Less, Protect More

The Advantest data breach disclosure delay is a reminder that the safest sensitive record is the one an organization never collects. Where you have a choice, ask whether a service really needs a full ID, and favor options that verify a single fact rather than collect a whole document.

That demand is visible among consumers. A recent survey found 67% want age checks without sharing full ID, a clear sign that people prefer data minimization. The same concern runs through policy debates, such as the SCREEN Act markup in the Senate, where age verification requirements could mean more identity data held by more companies.

Freeze your credit if you are affected, monitor your accounts, and push back when an organization asks for more ID than it needs.