Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2688+ Articles
165+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Swiss Rail Giant Stadler Refuses $12.3M Ransom Demand from Everest Group
Swiss Rail Giant Stadler Refuses $12.3M Ransom Demand from Everest Group
NEWS

Swiss Rail Giant Stadler Refuses $12.3M Ransom Demand from Everest Group

Stadler Rail has publicly rejected a CHF 10 million (~$12.3M USD) ransom demand from the Everest extortion group following a breach of a supplier...

Dylan H.

News Desk

July 23, 2026
4 min read

The Attack

Swiss rail manufacturer Stadler Rail has become the latest high-profile organization targeted by the Everest ransomware and extortion group — and has responded by publicly refusing to pay and filing a criminal complaint with Swiss police.

The incident occurred in mid-July 2026, when Everest breached a supplier data-exchange platform used by Stadler to share non-sensitive technical information with its supply chain partners. The attackers obtained access via stolen login credentials belonging to one of Stadler's suppliers.


What Was Stolen

Stadler's incident review determined that the scope of the breach was limited:

CategoryAffected
Non-sensitive supplier technical dataYes — exfiltrated
Personal dataNo
Safety-critical informationNo
In-service train systemsNo
Stadler IT systems or production linesNo

Stadler confirmed that its core IT environment, operational systems, and rolling stock were not impacted by the intrusion.


The Ransom Demand

Everest sent an extortion letter directly to Stadler demanding CHF 10 million (~$12.3 million USD) in exchange for not publishing the stolen data.

Stadler's response was unambiguous:

"Stadler will not pay any ransom under any circumstances and is therefore not susceptible to extortion."

The company immediately filed a criminal complaint with the Thurgau cantonal police and engaged external cybersecurity specialists to support the investigation.


About the Everest Group

The Everest group has been active since 2020 and has evolved over the years from a ransomware-and-encrypt model to a pure extortion / data leak operation — threatening to publish stolen data rather than encrypting victim systems.

Everest's Track Record

ItemDetail
Active since2020
ModelData theft extortion (no encryption)
Notable past targetsMajor European airports (Heathrow, Brussels)
Leak siteDark web — original site was defaced in April 2025
Known tacticsStolen credentials, supply chain / third-party access
Status (July 2026)Has not yet published Stadler data or claimed the attack publicly

Why Stadler's Response Matters

Stadler is a significant industrial target. The company employs approximately 18,000 people and reports annual revenues of around $4.9 billion. This is not the company's first brush with cybercriminals — Stadler suffered a prior cyberattack in 2020 — and the public refusal to pay reflects a hardened organizational stance.

Cybersecurity experts generally advise against paying ransoms for several reasons:

  1. Payment does not guarantee data deletion — exfiltrated data may still be sold or published
  2. Payment funds future attacks — ransomware groups reinvest proceeds
  3. No deterrence value — paying signals that extortion works against your organization
  4. Law enforcement consequences — in some jurisdictions, paying designated threat actor groups may have legal implications

Current Status

As of July 23, 2026:

  • Stadler has not appeared on Everest's dark web leak site
  • Everest has not made a public claim about the Stadler attack
  • The criminal investigation is ongoing with Thurgau cantonal police
  • Stadler continues to assess the full scope of the breach with external security specialists

Recommendations for Organizations

If your organization uses third-party supplier portals or data exchange platforms, this incident highlights key supply chain security risks:

  1. Enforce MFA on all supplier platform access — stolen credentials alone should not be sufficient to log in
  2. Segment supplier data platforms from core IT systems
  3. Audit third-party access regularly — remove dormant accounts and enforce least privilege
  4. Monitor for credential stuffing attacks against supplier portals
  5. Establish a ransomware response playbook in advance — do not negotiate under pressure

Sources

  • Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack — BleepingComputer
  • Stadler Everest ransom demand — Help Net Security
  • Stadler Rail refuses to pay $12.3 million ransom — SC World
  • Stadler Rail scoffs at Everest's $12.3M extortion attempt — The Register

Related Reading

  • Upbound Group Hack Triggers $13M in Fraudulent Contract Losses
  • Cybersecurity News Feed
#Ransomware#Everest#Stadler#Cybercrime#Extortion#Switzerland

Related Articles

Swiss Rail Giant Stadler Rejects $12.3M Ransom Demand After Cyberattack

Swiss rail vehicle manufacturer Stadler Rail has publicly refused to pay a CHF 10 million (~$12.3M USD) ransom demanded by the Everest ransomware group...

5 min read

Berlin Refuses to Pay Rhysida Ransom Over Alleged Senate Data Theft

Rhysida ransomware claims 5.7TB stolen from a Berlin Senate department; city officials say they will not pay the 30 BTC ransom demand.

3 min read

Swiss Government SharePoint Breach Compromised 200 Accounts

Switzerland's Federal IT Office confirms hackers exploited Microsoft SharePoint vulnerabilities to breach federal servers and compromise approximately 200 government accounts. An investigation is ongoing.

5 min read
Back to all News