2026 Synopsys — D1R ransomware leak-site claim; 40k corporate clients cited (unverified; Jul 13)
Data compromised
Actor-claimed: corporate client database (~40,000 entries) and customer technical/design data reachable via alleged Synopsys compromise—unverified; company stated claims of unauthorized customer confidential data access are unfounded
Technical writeup
Unverified ransomware leak-site claim — observed July 13, 2026. D1R, a newly observed ransomware/extortion group, listed Synopsys separately on its Tor leak site alongside Bosch, claiming attackers exploited a vulnerability in Synopsys' website registration form to exfiltrate a corporate client database of approximately 40,000 entries without internal network access. CyberNews published screenshots and actor messaging describing the claim; Ransomware.live indexed Synopsys as a D1R victim discovered July 13, 2026. On July 14, 2026, Synopsys told SecurityWeek it continuously monitors its network, has not been contacted by the threat actor, and found no evidence that Synopsys or customer technical data was subject to unauthorized access—calling claims of unauthorized access to customer confidential data unfounded. This D1R listing is distinct from Synopsys' verified 2025–2026 workforce email-account incident (`synopsys2025`). BreachHistory catalogs the actor-cited 40,000 client-database figure labeled unverified pending independent validation.
Root cause
Unverified D1R ransomware group leak-site listing alleging Synopsys website registration-form flaw exposed ~40,000 corporate client records—Synopsys denied unauthorized access Jul 14, 2026