Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack

Swiss Rail Giant Stadler Rejects $12.3M Ransom Demand After Cyberattack

Stadler Rail, a multinational Swiss train manufacturer, has been targeted by the Everest ransomware gang in a cyberattack that exposed sensitive information about one of its suppliers. In response to the attack, the company has refused to pay the extortion demand of around $12.3 million and filed a criminal complaint with local authorities.

According to Stadler’s statement, the attackers breached a data exchange platform shared with one of its suppliers, but fortunately, neither the company’s IT systems nor production operations were impacted. The stolen information is deemed non-security relevant by Stadler, and no personal data was compromised. The company emphasizes that its rail vehicles operating worldwide are not affected by the data theft, and global production continues as normal.

The Everest ransomware gang has been known to abandon network encryption tactics in favor of data theft, threatening victims with leaking stolen information unless a ransom is paid. In some cases, the group has even sold access to breached networks to other threat actors or acquired data from them to conduct their own extortion campaigns. Stadler Rail has not yet appeared on the gang’s extortion site.

This incident marks the second time in recent years that Stadler has been targeted by hackers. In 2020, an unknown hacking group infiltrated its IT systems, infected parts of its infrastructure with malware, and stole data from compromised devices. Although the case was initially suspected to be a ransomware attack, Stadler did not confirm it at the time.

The refusal to pay the ransom demand is a significant move by Stadler Rail in this incident. By doing so, the company demonstrates its commitment to not supporting the cybercrime ecosystem and sends a strong message to other threat actors that extorting money from them will not be tolerated. This stance highlights the importance of having robust cybersecurity measures in place, as well as a clear incident response plan, to minimize the impact of such attacks.

As a takeaway for security-conscious individuals and organizations, this incident serves as a reminder of the evolving tactics used by threat actors. It’s essential to regularly review and update your defenses against new and emerging threats, as well as to have a comprehensive incident response plan in place. Furthermore, having robust cybersecurity measures, such as proper data backup and access controls, can help minimize the impact of a cyberattack.


Source: Bleeping Computer — 2026-07-22