The Attack
Swiss rail manufacturer Stadler Rail has become the latest high-profile organization targeted by the Everest ransomware and extortion group — and has responded by publicly refusing to pay and filing a criminal complaint with Swiss police.
The incident occurred in mid-July 2026, when Everest breached a supplier data-exchange platform used by Stadler to share non-sensitive technical information with its supply chain partners. The attackers obtained access via stolen login credentials belonging to one of Stadler's suppliers.
What Was Stolen
Stadler's incident review determined that the scope of the breach was limited:
| Category | Affected |
|---|---|
| Non-sensitive supplier technical data | Yes — exfiltrated |
| Personal data | No |
| Safety-critical information | No |
| In-service train systems | No |
| Stadler IT systems or production lines | No |
Stadler confirmed that its core IT environment, operational systems, and rolling stock were not impacted by the intrusion.
The Ransom Demand
Everest sent an extortion letter directly to Stadler demanding CHF 10 million (~$12.3 million USD) in exchange for not publishing the stolen data.
Stadler's response was unambiguous:
"Stadler will not pay any ransom under any circumstances and is therefore not susceptible to extortion."
The company immediately filed a criminal complaint with the Thurgau cantonal police and engaged external cybersecurity specialists to support the investigation.
About the Everest Group
The Everest group has been active since 2020 and has evolved over the years from a ransomware-and-encrypt model to a pure extortion / data leak operation — threatening to publish stolen data rather than encrypting victim systems.
Everest's Track Record
| Item | Detail |
|---|---|
| Active since | 2020 |
| Model | Data theft extortion (no encryption) |
| Notable past targets | Major European airports (Heathrow, Brussels) |
| Leak site | Dark web — original site was defaced in April 2025 |
| Known tactics | Stolen credentials, supply chain / third-party access |
| Status (July 2026) | Has not yet published Stadler data or claimed the attack publicly |
Why Stadler's Response Matters
Stadler is a significant industrial target. The company employs approximately 18,000 people and reports annual revenues of around $4.9 billion. This is not the company's first brush with cybercriminals — Stadler suffered a prior cyberattack in 2020 — and the public refusal to pay reflects a hardened organizational stance.
Cybersecurity experts generally advise against paying ransoms for several reasons:
- Payment does not guarantee data deletion — exfiltrated data may still be sold or published
- Payment funds future attacks — ransomware groups reinvest proceeds
- No deterrence value — paying signals that extortion works against your organization
- Law enforcement consequences — in some jurisdictions, paying designated threat actor groups may have legal implications
Current Status
As of July 23, 2026:
- Stadler has not appeared on Everest's dark web leak site
- Everest has not made a public claim about the Stadler attack
- The criminal investigation is ongoing with Thurgau cantonal police
- Stadler continues to assess the full scope of the breach with external security specialists
Recommendations for Organizations
If your organization uses third-party supplier portals or data exchange platforms, this incident highlights key supply chain security risks:
- Enforce MFA on all supplier platform access — stolen credentials alone should not be sufficient to log in
- Segment supplier data platforms from core IT systems
- Audit third-party access regularly — remove dormant accounts and enforce least privilege
- Monitor for credential stuffing attacks against supplier portals
- Establish a ransomware response playbook in advance — do not negotiate under pressure
Sources
- Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack — BleepingComputer
- Stadler Everest ransom demand — Help Net Security
- Stadler Rail refuses to pay $12.3 million ransom — SC World
- Stadler Rail scoffs at Everest's $12.3M extortion attempt — The Register