Cybersecurity 1 h agoAdd to bookmarks

The Swiss train manufacturer Stadler Rail has been targeted by the Everest group via a data exchange platform with a supplier. It refuses to pay the 10 M CHF (~12.3 M$) demanded - and at this hour, Everest has not published anything on its leak site, which is unusual.
The Swiss train manufacturer Stadler Rail confirmed on July 23, 2026, that it had been targeted by the Everest ransomware group - a Russophone cluster active since approximately December 2020. The ransom demand amounts to 10 M CHF, approximately 12.3 M$. Stadler refused to pay.
According to the manufacturer's official communication:
Everest's usual scheme, when a target refuses to pay, is to publish the stolen data on its leak site to exert pressure. However, as of the publication date of The Register's article, Stadler does not appear on the group's site. This is an unusual deviation - either Everest is giving Stadler time to change its mind, or the stolen content has less extortion value than expected. This is the point we will follow in the coming weeks.
Only Stadler and one of its suppliers at this stage. Users of Stadler trains are not concerned - no passenger data, no railway operational data is at stake according to Stadler's communication.
Nothing specific on the user side. For security teams at manufacturers and industrial equipment suppliers, the incident reinforces two already known reflexes:
1. Map the portals for exchanging data with suppliers and activate multi-factor authentication on them, without exception. 2. Consider the credentials of third-party accounts as a critical asset - more and more incidents are entering through them, not through the perimeter firewall.
The case illustrates a recurring shift: when the central IT system is well maintained, the breach occurs through the value chain - a poorly supervised supplier portal is enough. Stadler's public refusal to pay also aligns with a European trend not to fuel the ransomware economy, even if it means accepting the publication of the data.
Article produced by artificial intelligence, reviewed under human editorial control.