< Back to all clusters
[TECHNOLOGY] · Switzerland · 4 sources

started · updated

Stadler Rail Rejects $12 Million Ransom Demand in Supplier Data Breach

Swiss train manufacturer Stadler Rail was targeted in mid‑July by the ransomware and extortion group Everest. The attackers gained access to a shared file‑exchange platform used by a third‑party supplier and stole technical documents belonging to that supplier, not Stadler’s own systems. Everest demanded a ransom of 10 million Swiss francs (about US$12.3 million) to refrain from publishing the stolen data. Stadler publicly refused to pay, stating that “under no circumstances will Stadler pay a ransom and therefore cannot be extorted.” The company filed a criminal complaint with the Thurgau cantonal police and announced that all production sites remain fully operational, with no loss of its own data or impact on train services worldwide. The incident underscores vulnerabilities in supply‑chain portals and follows a prior 2020 cyberattack on Stadler that also resulted in a ransom demand.