← Blog

Bosch D1R Claim: Synopsys Denies Breach Evidence

Share on X

Unverified claim — July 13–14, 2026: A newly observed ransomware group called D1R listed German engineering giant Bosch on its Tor leak site, alleging sensitive hardware-design data was stolen through an alleged breach of U.S. EDA vendor Synopsys. On July 14, 2026, Synopsys told SecurityWeek it found no evidence of unauthorized access to its systems or customer technical data and called the hackers' claims unfounded. Bosch had not confirmed a matching incident at indexing time.

What D1R claimed

According to CyberNews reporting published July 13, 2026, D1R gave Bosch an 11-day countdown on its dark-web leak site before allegedly publishing stolen files. Sample material included:

  • A page from a Controller Area Network (CAN) user manual — CAN is the vehicle/industrial bus protocol Bosch pioneered in the 1980s
  • Directory listings showing .vhd files and other hardware-design project artifacts that could, if authentic, expose VHDL source used in proprietary chip and embedded-system development

Crucially, D1R did not claim a direct intrusion into Bosch corporate networks. Instead, the group said the data came from an alleged Synopsys compromise — framing the incident as a supply-chain / third-party path into a major automotive and industrial supplier.

Ransomware.live indexed Bosch as a D1R victim discovered July 13, 2026. D1R itself is a new name in the extortion ecosystem with only a handful of listings at the time of reporting.

Separate Synopsys listing: 40,000 clients cited

D1R also listed Synopsys in a separate leak-site entry, claiming attackers exploited a flaw in Synopsys' website registration form to pull a corporate client database of roughly 40,000 entries without internal network access. Ransomware.live indexed that Synopsys listing the same day.

This D1R narrative is distinct from Synopsys' verified 2025–2026 workforce email-account breach, which involved unauthorized access to a small number of corporate mailboxes and U.S. regulator-filed consumer notices — not a 40,000-row client database dump on a leak site.

Synopsys denies the D1R claims

On July 14, 2026, Synopsys responded to SecurityWeek with a firm denial:

  • It continuously monitors its network
  • It has found no evidence that Synopsys or customer technical data was subject to unauthorized access
  • It had not been contacted by the threat actor
  • Based on its investigation, claims of unauthorized access to customer confidential data are unfounded

SecurityWeek further noted that a screenshot of a document the hackers posted as Bosch proof appears to match material already in the public domain — a recurring pattern when extortion groups recycle manuals or marketing PDFs to inflate credibility.

What Bosch said

When SecurityWeek asked Bosch incident-specific questions, the company declined to address the D1R listing directly and instead issued a general statement emphasizing continuous cybersecurity investment and coordinated incident response. That is not a confirmation of the leak-site claim, but it also does not rule out a private investigation.

Why the supply-chain angle matters

Synopsys sells electronic design automation software and semiconductor IP used by Bosch engineering teams to design and verify chips and embedded electronics in vehicles, appliances, and industrial gear. A genuine compromise at an EDA vendor — or exfiltration of customer project files stored in shared design workflows — could expose competitive IP and give attackers insight into hardware attack surfaces.

That is why even an unverified claim pairing Synopsys and Bosch draws attention: it mirrors real-world risk models where attackers target software/tooling providers to reach manufacturing customers. At catalog time, however, only the actors' Tor posts and trade-press reporting existed — not company-confirmed exfiltration.

What is not confirmed

  • No attested count of affected Bosch employees, customers, or design projects
  • No Bosch confirmation that proprietary .vhd or CAN engineering files were stolen
  • No independent forensic validation that the 40,000 Synopsys client rows are authentic
  • Synopsys' explicit denial that unauthorized access occurred

Treat D1R's listings as unverified extortion marketing until Bosch, Synopsys, or regulators publish attested findings.

Action items

  1. Do not download alleged leak archives from Tor sites, forums, or Telegram — files may contain malware or unrelated recycled documents.
  2. Semiconductor and automotive supply-chain teams should verify any vendor communication only through official Bosch and Synopsys channels.
  3. Watch for spear-phishing referencing CAN protocols, VHDL projects, or fake "Synopsys license audit" messages — common lures after high-profile EDA claims.
  4. Audit third-party EDA access if your organization shares design repositories with external tooling vendors.

Canonical records

Bosch 2026 D1R claim on BreachHistory · Synopsys 2026 D1R claim on BreachHistory — both indexed as unverified.

Sources: SecurityWeek, CyberNews, Ransomware.live (Bosch), Ransomware.live (Synopsys).