Swiss Rail Giant Stadler Rejects $12.3 Million Ransom Demand After Cyberattack

Stadler Rail, the Swiss manufacturer of trains and rail vehicles used by transit systems across Europe and beyond, has confirmed it was targeted by the Everest ransomware group, which demanded approximately $12.3 million after breaching a data-exchange platform the company shared with one of its suppliers. Stadler has said it will not pay the ransom.

Rather than compromising Stadler’s own core network directly, the attackers appear to have gained access through a shared third-party data platform used for exchanging files with a supplier — a pattern increasingly common in ransomware incidents, where attackers target the weaker link in a company’s supply chain instead of a well-defended primary network. Everest is a ransomware-as-a-service operation that has previously claimed responsibility for breaches at large organizations, typically relying on data theft and extortion rather than only file encryption to pressure victims into paying.

By publicly rejecting the ransom demand, Stadler joins a growing number of companies opting not to pay extortionists, a stance encouraged by law enforcement agencies but one that carries the risk that stolen data could be leaked or sold if the group follows through on its threats. It is not yet clear from available reporting what volume or type of data was exposed in the breach, or whether Stadler’s own operations or those of its rail customers were affected.

This summary is based on BleepingComputer’s reporting; additional detail may become available as Stadler and its supplier continue to investigate the incident.

Read the original report →