Swiss railway manufacturer Stadler Rail has confirmed that the Everest ransomware group demanded a ransom of approximately $12.3 million following a cyber attack on its data exchange platform shared with a supplier.
While the attackers have not publicly identified themselves, Stadler Rail received an extortion letter demanding a ransom of 10 million Swiss francs.
In a firm response, the company announced it would not comply with the ransom demand and has lodged a criminal complaint with the Thurgau cantonal police.
“Mr. Stadler will not pay the ransom under any circumstances and therefore is not a target for extortion,” the company stated.
Stadler Rail is a leading Swiss multinational railway manufacturer specializing in locomotives, trams, metros, passenger trains, and railway signaling systems. The company employs approximately 18,000 people and operates eight production facilities and six engineering sites, boasting annual revenues exceeding $4.9 billion.
The cyber incident, which occurred in mid-July, did not impact Stadler’s IT systems or production operations, allowing the company to continue its global activities without disruption.
According to the company’s official disclosure, only technical information unrelated to security was stolen from the affected supplier.
“No relevant personal data has been compromised. Stadler’s rolling stock in operation worldwide remains unaffected by the data breach. The company’s global production is continuing as normal,” they confirmed.
The Everest ransomware group emerged in 2020 and has shifted its operations from ransomware encryption tactics to data theft. They are now threatening victims with the release of stolen data unless a ransom is paid.
Previously, Everest acted as an initial access broker, selling access to compromised networks to other cybercriminals and using stolen data for extortion campaigns of their own.
After a disruption in April 2025 that led to the defacement of their dark web leak site, the Everest team has since migrated to a new domain, and as of now, Stadler Rail has not been listed on the gang’s extortion site.
In 2020, Stadler experienced a cybersecurity incident involving hackers who infiltrated its systems, deploying malware and taking data from compromised devices, although the company did not confirm it as a ransomware attack at that time.
Research shows that 54% of successful attacks are documented by security teams, with a mere 14% issuing warnings. The remaining threats often go undetected.
Picus’ whitepaper offers strategies to test your SIEM and EDR rules through breach simulations to ensure threats are not overlooked.
Source: www.bleepingcomputer.com




