Stadler Rail refuses the $12.3 million ransom from Everest - and the case takes an unusual turn

Cybersecurity 25 min agoAdd to bookmarks

Stadler Rail refuses the $12.3 million ransom from Everest - and the case takes an unusual turn
Illustration : Momiji Shirogane

The Swiss train manufacturer Stadler Rail has been targeted by the Everest group via a data exchange platform with a supplier. It refuses to pay the 10 M CHF (~12.3 M$) demanded - and at this hour, Everest has not published anything on its leak site, which is unusual.

The facts

The Swiss train manufacturer Stadler Rail confirmed on July 23, 2026, that it had been targeted by the Everest ransomware group - a Russophone cluster active since approximately December 2020. The ransom demand amounts to 10 M CHF, approximately 12.3 M$. Stadler refused to pay.

What was affected

According to the manufacturer's official communication:

  • Stadler's internal IT systems were not compromised and remained operational.
  • Production operations and rolling stock in circulation were not affected.
  • Access was gained through a data exchange platform with a supplier, using compromised credentials.
  • The exfiltrated data concerns technical information from an unnamed supplier.
  • Stadler states that "no data relevant to security" is affected and no personal data has been stolen.

An anomaly to note

Everest's usual scheme, when a target refuses to pay, is to publish the stolen data on its leak site to exert pressure. However, as of the publication date of The Register's article, Stadler does not appear on the group's site. This is an unusual deviation - either Everest is giving Stadler time to change its mind, or the stolen content has less extortion value than expected. This is the point we will follow in the coming weeks.

Who is impacted

Only Stadler and one of its suppliers at this stage. Users of Stadler trains are not concerned - no passenger data, no railway operational data is at stake according to Stadler's communication.

What to do

Nothing specific on the user side. For security teams at manufacturers and industrial equipment suppliers, the incident reinforces two already known reflexes:

What to do now

1. Map the portals for exchanging data with suppliers and activate multi-factor authentication on them, without exception. 2. Consider the credentials of third-party accounts as a critical asset - more and more incidents are entering through them, not through the perimeter firewall.

Analysis

The case illustrates a recurring shift: when the central IT system is well maintained, the breach occurs through the value chain - a poorly supervised supplier portal is enough. Stadler's public refusal to pay also aligns with a European trend not to fuel the ransomware economy, even if it means accepting the publication of the data.

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Was this article helpful?

5 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information