Operations Remain Uninterrupted

Stadler Rail Rejects $12.3 Million Ransom Demand After Cyberattack

Ransom, Stadler Rail cyberattack 2026, Stadler Rail rejects ransom demand, Everest group data theft, Everest group, Stadler Rail, Ransomware
Facebook
X
LinkedIn
Reddit
WhatsApp

Swiss train manufacturer Stadler Rail has rejected a ransom demand of 10 million Swiss francs, equivalent to approximately $12.3 million US dollars, from the Everest group following a data breach at a supplier.

Swiss rail vehicle manufacturer Stadler Rail was targeted in a security incident in mid-July 2026. According to the company, attackers gained access through a data exchange platform shared with one of its suppliers. Technical information was stolen during the incident. Stadler’s internal IT systems and global production operations were not affected by the breach. The company provided the following statement on the scope of the data exposure:

Ad

“No relevant personal data was stolen. Stadler’s rail vehicles operating worldwide are not affected by the data theft. Stadler’s global production continues to operate normally.”

Stadler

Ad

Everest Hackers Demand Ransom as Stadler Files Police Report

Following the incident, the train manufacturer received an extortion letter from the Everest hacking group. The attackers demanded a ransom of 10 million Swiss francs, equivalent to approximately $12.3 million US dollars. Stadler refused to make the payment and filed a criminal complaint with the Thurgau Cantonal Police.

Addressing its stance on extortion attempts, the company said: “Stadler will under no circumstances pay a ransom and is therefore not susceptible to extortion.”

The Everest group emerged as a ransomware actor in 2020 but has since shifted its focus primarily to data theft and extortion without encrypting victims’ systems.

Stadler Rail Maintains Operations and Protects Vehicle Systems

Stadler employs around 18,000 people across eight production sites and six development locations and generates annual revenue of more than $4.9 billion US dollars. The systems used in its locomotives, trams, subway trains and signaling technology delivered worldwide operate independently of the affected data exchange platform. The company was previously targeted in a cyberattack against its IT infrastructure in 2020.

(ll)

Ad

Artikel zu diesem Thema

Weitere Artikel