Skip to content
Supply chainContained

Stadler Rail supplier-platform breach and CHF 10 million Everest extortion

Swiss train manufacturer Stadler Rail confirmed that attackers used compromised credentials to steal technical data from a platform shared with a supplier, and refused a ransom demand of about $12.3 million from the Everest gang.

Victim
Stadler Rail AG

On 22 July 2026, Swiss rolling-stock manufacturer Stadler Rail confirmed a cyberattack in which intruders used compromised login credentials to access a data-exchange platform shared with one of its suppliers in mid-July. The attackers stole technical information that Stadler described as not security-relevant and belonging largely to the supplier, and the company said no relevant personal data was taken.

The Everest gang, which began as a ransomware operation in 2020 and has since shifted to data-theft extortion, demanded 10 million Swiss francs (about $12.3 million). Stadler rejected the demand outright, stating that it "will not pay any ransom under any circumstances," and filed a criminal complaint with the Thurgau cantonal police.

Impact

Stadler, which employs about 18,000 people and reports more than $4.9 billion in annual revenue, said neither its own IT systems nor its global production were affected and that operations continued normally. The company had previously been hit by a cyberattack in 2020.

Why it matters

The incident shows how shared collaboration platforms with suppliers create an attack surface that sits partly outside a manufacturer's own controls: a single set of stolen credentials was enough to reach engineering data. Stadler's public, unconditional refusal to pay also illustrates how a clear no-payment policy can blunt data-theft extortion when the stolen material has limited value to the attackers.

Financial impact

Reported costs in USD

Ransom demanded
$12.3M
Ransom paid
Refused

    Timeline

    1. Attackers use compromised login credentials to access a data-exchange platform Stadler shares with one of its suppliers and steal technical information.

    2. Stadler confirms the incident, says it will not pay the CHF 10 million (about $12.3 million) demanded by Everest, and files a criminal complaint with the Thurgau cantonal police.

    Sources

    1. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/swiss-rail-giant-stadler-rejects-123m-ransom-demand-after-cyberattack/
    2. theregister.comhttps://www.theregister.com/security/2026/07/23/stadler-rail-scoffs-at-eversts-123m-extortion-attempts/5276922
    3. scworld.comhttps://www.scworld.com/brief/stadler-rail-refuses-to-pay-12-3-million-ransom-after-ransomware-attack

    Related incidents

    Supply chainContained

    DAEMON Tools official installers trojanized in month-long supply-chain attack

    Kaspersky revealed that signed installers downloaded from the official DAEMON Tools website had carried a backdoor since 8 April 2026, infecting thousands of machines in more than 100 countries and delivering follow-on implants, including QUIC RAT, to about a dozen selected targets.

    Victim
    DAEMON Tools (AVB Disc Soft) users