Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2023+ Articles
153+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Swiss Rail Giant Stadler Refuses $12.3M Ransom Demand from Everest Group
Swiss Rail Giant Stadler Refuses $12.3M Ransom Demand from Everest Group
NEWS

Swiss Rail Giant Stadler Refuses $12.3M Ransom Demand from Everest Group

Stadler Rail has publicly rejected a CHF 10 million (~$12.3M USD) ransom demand from the Everest extortion group following a breach of a supplier data-exchange platform. The company filed a criminal complaint instead of paying.

Dylan H.

News Desk

July 23, 2026
4 min read

The Attack

Swiss rail manufacturer Stadler Rail has become the latest high-profile organization targeted by the Everest ransomware and extortion group — and has responded by publicly refusing to pay and filing a criminal complaint with Swiss police.

The incident occurred in mid-July 2026, when Everest breached a supplier data-exchange platform used by Stadler to share non-sensitive technical information with its supply chain partners. The attackers obtained access via stolen login credentials belonging to one of Stadler's suppliers.


What Was Stolen

Stadler's incident review determined that the scope of the breach was limited:

CategoryAffected
Non-sensitive supplier technical dataYes — exfiltrated
Personal dataNo
Safety-critical informationNo
In-service train systemsNo
Stadler IT systems or production linesNo

Stadler confirmed that its core IT environment, operational systems, and rolling stock were not impacted by the intrusion.


The Ransom Demand

Everest sent an extortion letter directly to Stadler demanding CHF 10 million (~$12.3 million USD) in exchange for not publishing the stolen data.

Stadler's response was unambiguous:

"Stadler will not pay any ransom under any circumstances and is therefore not susceptible to extortion."

The company immediately filed a criminal complaint with the Thurgau cantonal police and engaged external cybersecurity specialists to support the investigation.


About the Everest Group

The Everest group has been active since 2020 and has evolved over the years from a ransomware-and-encrypt model to a pure extortion / data leak operation — threatening to publish stolen data rather than encrypting victim systems.

Everest's Track Record

ItemDetail
Active since2020
ModelData theft extortion (no encryption)
Notable past targetsMajor European airports (Heathrow, Brussels)
Leak siteDark web — original site was defaced in April 2025
Known tacticsStolen credentials, supply chain / third-party access
Status (July 2026)Has not yet published Stadler data or claimed the attack publicly

Why Stadler's Response Matters

Stadler is a significant industrial target. The company employs approximately 18,000 people and reports annual revenues of around $4.9 billion. This is not the company's first brush with cybercriminals — Stadler suffered a prior cyberattack in 2020 — and the public refusal to pay reflects a hardened organizational stance.

Cybersecurity experts generally advise against paying ransoms for several reasons:

  1. Payment does not guarantee data deletion — exfiltrated data may still be sold or published
  2. Payment funds future attacks — ransomware groups reinvest proceeds
  3. No deterrence value — paying signals that extortion works against your organization
  4. Law enforcement consequences — in some jurisdictions, paying designated threat actor groups may have legal implications

Current Status

As of July 23, 2026:

  • Stadler has not appeared on Everest's dark web leak site
  • Everest has not made a public claim about the Stadler attack
  • The criminal investigation is ongoing with Thurgau cantonal police
  • Stadler continues to assess the full scope of the breach with external security specialists

Recommendations for Organizations

If your organization uses third-party supplier portals or data exchange platforms, this incident highlights key supply chain security risks:

  1. Enforce MFA on all supplier platform access — stolen credentials alone should not be sufficient to log in
  2. Segment supplier data platforms from core IT systems
  3. Audit third-party access regularly — remove dormant accounts and enforce least privilege
  4. Monitor for credential stuffing attacks against supplier portals
  5. Establish a ransomware response playbook in advance — do not negotiate under pressure

Sources

  • Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack — BleepingComputer
  • Stadler Everest ransom demand — Help Net Security
  • Stadler Rail refuses to pay $12.3 million ransom — SC World
  • Stadler Rail scoffs at Everest's $12.3M extortion attempt — The Register

Related Reading

  • Upbound Group Hack Triggers $13M in Fraudulent Contract Losses
  • Cybersecurity News Feed
#Ransomware#Everest#Stadler#Cybercrime#Extortion#Switzerland

Related Articles

Anubis Ransomware Claims Coca-Cola Fairlife Attack, Threatens Data Leak

The Anubis ransomware gang claims responsibility for a cyberattack on Coca-Cola's Fairlife dairy subsidiary, threatening to publish stolen corporate data unless a ransom is paid.

5 min read

Former DigitalMint Ransomware Negotiator Pleads Guilty to $75.3M Extortion Scheme

Angelo Martino, a former ransomware payment negotiator for DigitalMint, has pleaded guilty to helping accomplish extort $75.3 million in ransom from five...

4 min read

How Enterprise GenAI Can Amplify Ransomware Risk — and How to Contain It

Enterprise AI assistants and agents that inherit excessive permissions or compromised identities create new ransomware attack paths. Identity controls, least-privilege access, and AI governance are now frontline defenses.

5 min read
Back to all News