New Ransomware Group D1R Claims Synopsys Breach, Threatens to Leak Bosch Data

New Ransomware Group D1R Claims Synopsys Breach, Threatens to Leak Bosch Data

A previously unknown ransomware group calling itself D1R claims it exploited a logic flaw in a Synopsys registration form to pull a 40,000-entry customer database, and separately says it used that access to obtain engineering data belonging to Bosch, though Synopsys says its investigation found no evidence of a breach.

Facts

FieldDetail
Threat actorD1R, a newly identified group with three listed victims
Claimed initial accessLogic flaw in a Synopsys registration form
Claimed data volume40,000 corporate client database entries
Secondary targetBosch, allegedly via data obtained from Synopsys
Response window given to victims11 days before threatened publication
Synopsys’s positionInvestigation found no evidence of unauthorized access to customer data

In mid-July 2026, a ransomware group calling itself D1R listed Synopsys, Bosch and, according to one threat-intelligence tracker, chipmaker ARM on its Tor-based leak site. D1R claims it exploited a flawed logic issue in a Synopsys website registration form to extract an entire corporate client database of 40,000 entries without needing internal system access, according to reporting from SecurityWeek and teiss. Separately, the group says it used data obtained through Synopsys to access material it describes as valuable intellectual property belonging to Bosch, the German engineering and technology company that relies on Synopsys electronic design automation tools to design vehicle and industrial components.

Synopsys said it has investigated the claims and found no evidence supporting them, stating it has not been contacted by the threat actor and considers the allegations of unauthorized customer data access unfounded. Bosch has not addressed the specifics of the claim, instead offering a general statement about its ongoing cybersecurity investments. Cybernews reported that a screenshot D1R provided as proof of Bosch access appears to show the first page of a publicly available Controller Area Network user manual rather than confidential material, raising doubt about the scope of any genuine access.

Figure 1. D1R gave both listed victims an 11-day countdown to respond.

A pattern of exaggerated extortion claims

D1R is a newly identified name in the ransomware landscape, with only three victims currently listed on its leak site, and little else publicly known about the group’s origin or affiliations. Security outlet SC Media noted that inflating or fabricating breach claims is a common extortion tactic, intended to pressure a named victim into contact and payment even when the underlying access is limited or unverified. This is not the first time Bosch’s name has surfaced in a data-related claim; the company was previously named in connection with a 2025 breach at Red Hat that exposed GitLab repository data covering roughly 800 customer networks, and in 2021 source code from a Bosch IoT connectivity platform reportedly appeared on an illicit marketplace.

What organizations should take from this

Treat unverified leak-site claims as requiring independent forensic confirmation before assuming a breach occurred, since extortion groups routinely pad or fabricate scope to increase pressure. Organizations using third-party design and engineering software, particularly platforms like Synopsys that sit upstream of multiple manufacturing clients, should confirm with vendors directly rather than relying on a threat actor’s public claims, and should review access logs for their own registration and customer-facing web forms for anomalous data-pull activity.

Leave a Reply

Your email address will not be published.