A major Swiss rail manufacturer, Stadler Rail, has recently faced a significant cybersecurity threat after being targeted by the Everest ransomware gang. The attackers breached a data exchange platform shared with one of Stadler’s suppliers, and demanded a staggering $12.3 million in exchange for not releasing stolen data. However, in a bold move, Stadler has refused to pay the ransom and has instead filed a criminal complaint with local authorities.
Stadler Rail is a multinational company that employs over 18,000 people worldwide and has an annual revenue of over $4.9 billion. The company’s IT systems and production operations were not impacted by the breach, and normal business activities continue globally. According to Stadler, the hackers stole only technical information from its supplier, which is not security-sensitive. Crucially, no personal data was compromised in the attack.
The Everest ransomware gang has been active since 2020, initially operating as a traditional ransomware outfit but later shifting its tactics to focus on data theft and extortion. The group has developed a reputation for threatening victims with public disclosure of stolen data unless a ransom is paid. In some cases, Everest has even sold access to breached networks to other threat actors or acquired stolen data from other groups to conduct its own extortion campaigns.
This attack highlights the evolving nature of cyber threats. Ransomware gangs are no longer content with simply encrypting data and demanding a payment for the decryption key. Instead, they are now seeking to maximize their profits by stealing sensitive information and using it as leverage against their victims. This approach makes it even more challenging for organizations to respond effectively to these types of attacks.
Stadler’s decision not to pay the ransom is a significant development in this case. By refusing to give in to the attackers’ demands, Stadler has sent a strong message that it will not be extorted or bullied into paying a hefty sum for stolen data. This stance should serve as an inspiration to other organizations facing similar threats.
As a practical takeaway from this incident, organizations must take proactive steps to protect themselves against these types of attacks. This includes implementing robust cybersecurity measures, conducting regular threat hunting exercises, and ensuring that all employees are aware of the risks associated with data breaches. By being prepared and vigilant, businesses can minimize their exposure to cyber threats and reduce the likelihood of falling victim to ransomware gangs like Everest.
Source: Bleeping Computer — 2026-07-22