← Bosch

2026 Bosch — D1R ransomware leak-site claim via alleged Synopsys supply chain (unverified; Jul 13)

2026 Unknown records affected Share on X

Data compromised

Actor-claimed: CAN user manual sample, .vhd/VHDL hardware-design project files, and proprietary Bosch engineering IP—unverified; SecurityWeek noted posted manual appears publicly available

Technical writeup

Unverified ransomware leak-site claim — observed July 13, 2026. The newly surfaced D1R ransomware group listed Robert Bosch GmbH on its Tor leak site with an 11-day countdown, alleging valuable engineering and intellectual-property data stolen via an alleged breach of U.S. EDA vendor Synopsys rather than a direct Bosch intrusion. CyberNews reported sample files including a Controller Area Network (CAN) user-manual page and directory listings with .vhd and other hardware-design project files. Ransomware.live indexed Bosch as a D1R victim discovered July 13, 2026. On July 14, 2026, Synopsys told SecurityWeek it found no evidence of unauthorized access to Synopsys or customer technical data and called the claims unfounded; SecurityWeek noted a posted Bosch document sample appears to match material already in the public domain. Bosch declined incident-specific questions and issued a general cybersecurity statement. No attested victim count was available at indexing time. BreachHistory indexes recordsAffected 0 until company- or regulator-attested scope emerges.

Root cause

Unverified D1R ransomware group leak-site listing alleging Bosch engineering/IP data obtained through an alleged Synopsys breach—neither company confirmed at catalog time; Synopsys denied unauthorized access Jul 14

References