Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack

3 hours ago 4

Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack

Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers.

The threat actor has not publicly claimed the attack, but the Swiss company says that it received an extortion letter from Everest ransomware asking for a ransom of 10 million Swiss francs.

The company responded by saying that it will not pay the threat actor and filed a criminal complaint with the Thurgau cantonal police.

image

"Stadler will not pay any ransom under any circumstances and is therefore not susceptible to extortion."

Stadler Rail is a large, multinational Swiss train manufacturer that builds locomotives, trams, metro trains, passenger trains, and railway signaling systems.

The company supplies rail operators worldwide, employs 18,000 people working in 8 production facilities and 6 engineering sites, and has an annual revenue of over $4.9 billion.

Stadler said that the incident occurred in mid-July and neither its IT systems nor its production operations were impacted, and continue as normal globally.

According to the company's disclosure, the hackers stole from a supplier only technical information that is not security relevant.

"No relevant personal data was stolen. Stadler's rail vehicles operating worldwide are not affected by the data theft. Stadler's global production continues as normal."

Everest is a threat group that emerged in 2020 as a ransomware operation but abandoned the network encryption tactic in favor of data theft. The gang now threatens victims with leaking the stolen data unless a ransom is paid.

In the past, Everest sold its access to the networks it breached to other threat actors, acting as an initial access broker. Sometimes, the hackers acquired data stolen by other threat actors to conduct their own extortion campaigns.

Currently, the Everest ransomware gang is operating a new domain, after its original dark web leak site was defaced in April 2025 with the message: "Don't do crime CRIME IS BAD xoxo from Prague." Stadler Rail is not yet listed on the gang's extortion site.

In 2020, Stadler suffered a cybersecurity incident where an unknown hacking group infiltrated its IT systems, infected parts of its infrastructure with malware, and stole data from compromised devices.

The case appeared to be a ransomware attack, though Stadler did not confirm it at the time.

article image

Test every layer before attackers do

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Read Entire Article