D1R — Ransomware Profile
D1R is an extortion crew first observed in July 2026, when its Tor-based data-leak site listed three marquee targets at once on July 13: Synopsys, Bosch and ARM. Per SecurityWeek, the group said it had breached a Synopsys website through a vulnerability, accessing a corporate client database of some 40,000 entries, and had used that data to obtain Bosch intellectual property, threatening leaks unless paid. Synopsys investigated and reported no evidence of unauthorized access, noting the actor never contacted it, and a document D1R posted as proof appeared to be publicly available material, per the same report; Bosch offered only a generic statement. WatchGuard's ransomware tracker classifies the emerging group as a data broker practicing direct and double extortion. All listings remain unverified leak-site claims, with at least three companies named to date.
IntelFusions coverage (1)
Recent claimed victims
Vendor research
Read the full analysis on IntelFusions