← Synopsys

2025–2026 Synopsys — unauthorized access to small number of corporate email accounts (Jun–Dec 2025); U.S. regulator-filed notices (Apr 2026)

2025 Unknown records affected Share on X

Data compromised

Potentially names, SSN/driver’s license or state ID, DOB, postal/email address, bank/financial, and medical or health-insurance details as listed in sample state notifications—varies by person

Technical writeup

Synopsys, Inc. regulatory breach notifications filed in early April 2026 (e.g., sample letters archived by New Hampshire and Massachusetts consumer-protection programs) described discovery around December 3, 2025, of suspicious activity tied to a limited set of workforce email accounts accessed without authorization roughly between June 17, 2025, and December 4, 2025. Issuers stated that messages or file store attachments in those mailboxes could have contained varied combinations of HR-/benefits-style PII and related categories depending on the individual (names, government IDs, financial or health-plan fields in typical U.S. corporate notices). Headcounts were not uniformly published in the same filings; treat as an enterprise email-compromise class incident with downstream PII exposure risk rather than a single-row “total affected” database dump.

Root cause

Unauthorized access to a small number of corporate email accounts (per company/regulatory notice narratives)

References