The group calling itself d1r surfaced on tracking systems on July 12, 2026, and within that single day claimed three victims: Bosch, ARM, and Synopsys. No sector or country metadata has been attributed to these claims, and no prior activity exists on record, making this a first-week appearance rather than an established pattern. No MITRE ATT&CK techniques have been catalogued for this actor, and no independent description of its tooling, extortion model, or leak-site infrastructure is currently available. The victim set, spanning semiconductor design and industrial technology firms, suggests a possible interest in high-value intellectual-property targets, though this remains an observation drawn solely from the claims themselves and is unverified. All victim designations here reflect the group's own claims and carry no independent confirmation of compromise.