TARGETLIST.txt), D1R claimed to have identified and subsequently breached Bosch and Arm as downstream targets .The group posted what it claimed was Bosch CAN module implementation code on its leak site, saying it was releasing it "for free for every engineer and car enthusiast" .
Synopsys publicly stated that its investigation found no evidence of unauthorized access to its systems or any customer technical data . Key details from multiple cybersecurity news outlets:
The situation is complicated by the fact that Synopsys had a separate, real data breach in early 2026 (disclosed to Massachusetts regulators in April 2026) involving exposed Social Security numbers and medical information — but that was a different incident and is not connected to D1R's July claims .
Bosch did not issue a detailed public denial. According to dark web monitoring sources, the company was given 11 days to make contact and negotiate . Security reporting indicates Bosch was investigating the claims but had not confirmed any direct intrusion into its own systems . As of the most recent reporting (July 14-15, 2026), no major data leak of Bosch intellectual property had been independently verified .
Arm was listed as a victim, but D1R's specific claims regarding Arm received less independent verification compared to the Bosch allegations .
| Element | Status |
|---|---|
| D1R's claim | Breached Synopsys via a web vulnerability, stole a 40K-entry client DB, then used that to pivot into Bosch and Arm. |
| Synopsys's position | Investigation found no evidence of any breach. The threat actor never contacted Synopsys . |
| Bosch's position | Investigating; no confirmation of a direct compromise. D1R posted what it claims is Bosch CAN code on its leak site . |
| D1R's proof | Widely assessed as weak — the screenshots appear to be rehashed or fabricated . |
| Arm's status | Listed as a victim, but D1R's specific claims regarding Arm received less independent verification . |
| Bottom line | Unsubstantiated claims, unresolved. The weight of evidence (Synopsys's internal investigation, D1R's lack of credible proof, the absence of a ransom demand) suggests D1R may be exaggerating or fabricating its access. However, supply-chain extortion cannot be fully ruled out until Bosch and Arm complete their own investigations. |
Synopsys firmly denies the breach and has found no evidence to support D1R's claims. Bosch is still assessing. Independent analysts have cast significant doubt on D1R's credibility, but the situation remains open as of July 15, 2026.