Hackers blackmail Bosch as secret engineering files surface on the dark web
Hackers give an ultimatum to German engineering giant.

- D1R ransomware gang claims it stole Bosch engineering data through an alleged breach of Synopsys.
- The group gave Bosch 11 days to negotiate before it allegedly publishes the data on its leak site.
- Sample files suggest possible exposure of hardware communication manuals and design files, but the breach scope remains unconfirmed.
- If legitimate, the files could help competitors or attackers study Bosch hardware used in appliances, vehicles, and embedded systems.
A ransomware gang claims to have stolen sensitive engineering data from Bosch through an alleged breach of Synopsys, a technology company. This raises concerns that proprietary hardware designs could be exposed.
The D1R ransomware gang listed Bosch, a German multinational engineering giant, on its dark web leak site, giving the company 11 days to make contact and negotiate before the data is allegedly published.
The provided data sample is quite concerning, as the document appears to relate to hardware communication used in Bosch products. However, the scope of the alleged breach is still unconfirmed.
Among the files is a screenshot showing the first page of a Controller Area Network (CAN) user manual. CAN is an industry-standard communication protocol originally developed by Bosch in 1983.
It enables electronic components to communicate with one another and is widely used in vehicles, including cars, trains, and aircraft. The protocol also powers communication between components in numerous embedded systems and consumer devices.
"These networks are mainly used for communication between multiple hardware components, so in Bosch's context, this could relate to products ranging from household appliances to automotive components," Cybernews researchers said.
Hardware design files raise additional concerns
The ransomware gang also published a directory listing of stolen files. Researchers noted that the filenames include numerous .vhd files alongside other project files.
These files could include VHDL source code, which is used to design hardware via code. If proved to be legitimate, such files could reveal details about proprietary hardware development.
"This increases the risk of exposing how Bosch designs its hardware, which could be valuable both to competitors and to attackers interested in hardware hacking," Cybernews researchers said.
Attackers claim a third-party breach
If true, the incident could be classified as a third-party supply chain breach, where attackers compromise a technology provider to gain access to customer data.
Rather than claiming a direct intrusion into Bosch's systems, D1R says the data was obtained through an alleged breach of Synopsys, a US-based company whose software is widely used for semiconductor and electronic design automation.
The gang also listed Synopsis in a separate entry, claiming to have exfiltrated a database of 40,000 corporate clients. The same 11-day countdown was set for this entry, while attackers provided a list of client databases as proof of their claims.
“Our cybersecurity assessment team has discovered a vulnerability in Synopsis,” attackers said. “A flawed logic in their registration form has allowed our team to pull an entire 40,000 corporate client database without internal access.”
Bosch response leaves more questions than answers
Cybernews reached out to Bosch and Synopsis for a comment. Bosch spokesperson has responded refusing to comment, which does not clarifies the situation regarding alleged incident.
"I ask for your understanding, that we generally don’t comment on cybersecurity topics," the spokesperson said.
"Bosch places great importance on cybersecurity. As a globally networked industrial company, Bosch continuously strengthens the protection of its digital systems and expands its capabilities to respond quickly and in a coordinated manner to potential cyber incidents. The goal is to protect critical systems based on risk and limit the impact of potential attacks," they added.
Hackers have targeted Bosch before
It is not the first time the Bosch name appears on illicit communication channels. Last year, cybercriminals claimed on Telegram that they had snatched sensitive data about approximately 800 customers' networks.
Bosch was among those affected. The data came from a US software company, Red Hat. The breach, confirmed by the company, affected GitLab repositories. Among the stolen data were various configuration files and internal tools.
In 2021, reportedly, a threat actor listed on an illicit marketplace source code exfiltrated from Bosch’s 5G IoT connectivity platform.
Updated on July 14th [16:00 p.m. GMT+2] with a statement from Bosch.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.