- Cybersecurity Docket
- Posts
- Ransomware Gang Claims It Stole Sensitive Engineering Data from Bosch
Ransomware Gang Claims It Stole Sensitive Engineering Data from Bosch
Plus, new data shows organizations were hit by an average 2,270 attacks per week in June.

Good morning! Here’s what’s up.

People
Tom Blomfield is leaving Y Combinator, where he has been a general partner since 2023, to join the compute team at Anthropic, where he will “focus on scaling the availability of computing power,” according to Business Insider. Blomfield co-founded British fintech company Monzo in 2015 and served as its CEO until 2020.

Clips ✂️
Hackers threaten to leak Bosch engineering data after alleged Synopsys hack
A ransomware gang claims to have stolen sensitive engineering data from Bosch through an alleged breach of technology company Synopsys. This raises concerns that proprietary hardware designs could be exposed.
D1R ransomware gang listed a German multinational engineering giant, Bosch, on its dark web leak site, giving the company 11 days to make contact and negotiate before the data is allegedly published.
The provided data sample is quite worrying, as the document appears to be related to hardware communications used in Bosch products. However, the scope of the alleged breach is still unconfirmed.
Among the files is a screenshot showing the first page of a Controller Area Network (CAN) user manual. CAN is an industry-standard communication protocol originally developed by Bosch in 1983.
It enables electronic components to communicate with one another and is widely used in vehicles, including cars, trains, and aircraft. The protocol also powers communication between components in numerous embedded systems and consumer devices.
New ransomware leader emerges as global cyberattacks rise in June 2026
Global cyberattacks increased during June 2026, with organisations experiencing an average of 2,270 attacks per week, according to Check Point Research. The company’s latest threat intelligence report found this represented a 10% increase compared with May and a 17% rise year on year, indicating a broad resurgence in attacker activity after a quieter period.
According to the report, the increase was not confined to a single industry or region. Instead, attack volumes rose across multiple sectors and geographies, suggesting threat actors are broadening their targeting strategies.
“June’s data shows a broad rebound in cyber activity, not a single isolated spike,” said Mark Mitchell, Security Engineer, Check Point Software. “Attackers are widening their reach across regions and industries, while ransomware groups continue to reorganise and scale.
The rise of The Gentlemen to the top of the ransomware leaderboard is a clear reminder that new operators can rapidly become major global threats. Organisations need prevention-first, AI-driven security that protects networks, users, data and AI workflows before attacks can cause impact.”
Another massive data breach exposed millions of driver's license numbers
U.S. insurance provider AssuranceAmerica has confirmed a data breach affecting the personal information and driver’s license numbers of 6.9 million people, making it the largest known spill of Americans’ driver’s license information this year.
Founded in 1998, AssuranceAmerica provides car and rental insurance to customers across more than a dozen U.S. states. As a large insurance provider, the company handles large amounts of information about prospective insurance customers and vehicle drivers, including their personal information and details about their state-issued driver’s licenses. In the hands of a malicious person, a driver’s license number can be used for fraud and impersonation.
In a data breach notice sent to customers and seen by TechCrunch, AssuranceAmerica said it discovered hackers in its computer systems on March 17. The company concluded its investigation on June 15, finding that the hackers had stolen customers’ names, contact information, and driver’s license numbers.
EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying Campaign
The European Union on Monday imposed sanctions on Russian military intelligence officers, hackers and private companies, denouncing what it called a yearslong cyber espionage campaign to undermine the bloc.
The move targeted nine people and four entities accused of links to an online spying network that the EU said has targeted governments and carried out sabotage operations against critical infrastructure like heating and power plants since 2010.
The European Council said in a statement that those targeted “contribute to Russia’s efforts to destabilize the EU, its member states and international partners.” The espionage and attacks have taken place in at least nine countries.
The names of the individuals and entities — which usually companies, government agencies, banks or other organizations — were not listed on the statement.
It said France, Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania and Finland, “among others” have been targeted.
Healthcare ransomware attacks rose 14% in first half of 2026, report finds
Healthcare organizations experienced 410 ransomware attacks during the first six months of 2026, a 14% increase from the second half of 2025, according to a report published by Comparitech. The data suggests ransomware activity has remained consistently high across the sector.
Of the reported incidents, 247 targeted hospitals, clinics and other healthcare providers, while 163 affected healthcare businesses, including pharmaceutical manufacturers, medical billing firms and health technology companies. Attacks against providers increased about 3% from the previous six-month period, while attacks on healthcare businesses climbed nearly 35%.
Comparitech identified 55 confirmed attacks against providers and 22 confirmed attacks against healthcare businesses. Those confirmed incidents exposed at least 424,740 patient records at providers and 154,825 records at healthcare businesses. The report defines confirmed attacks as those acknowledged by the affected organization or otherwise matching a publicly disclosed ransomware incident.
Data breach at Lidl: online store customer data stolen
Lidl is warning customers about a data breach at an external IT service provider. Unknown individuals gained access to the names, phone numbers, email addresses, dates of birth, and customer numbers of online store customers in the Netherlands, Belgium, and Germany. According to the supermarket chain, passwords, addresses, and payment information were not compromised.
The German supermarket chain reported the incident this week on its Dutch, Belgian, and German websites. According to Lidl, unknown individuals briefly gained access to a separately stored file containing customer data. It is explicitly not a hack of the online store itself. Lidl became aware of the breach earlier this week. The company has not disclosed how many customers are affected or which IT service provider was compromised.
Such details often come to light later. Ransomware gangs and other cybercriminals frequently make a habit of publicly naming their victims. In ransomware incidents, this puts additional pressure on the victim to pay the ransom in order to limit further reputational damage.
