Jul 23, 2026
Policy

Stadler refuses $12.3 million ransom after supplier data breach

The Swiss rail manufacturer said Everest obtained supplier technical data through compromised credentials, but its own IT systems and production were unaffected.

Renata Fuchs

By Renata Fuchs · Policy Reporter

· 3 min read

Stadler refuses $12.3 million ransom after supplier data breach
Photo: The Register

Swiss train maker Stadler Rail said it rejected a CHF 10 million, or about $12.3 million, ransom demand from the Everest ransomware group after attackers accessed technical data tied to one of its suppliers. The case is a reminder that supply chain access and shared data platforms remain useful extortion paths even when a target’s core systems are not breached.

Stadler said the incident involved “technical information from a supplier” and that no security-relevant data was affected. The company also said no relevant personal data was stolen, its IT systems were not compromised, and the incident did not affect the operation of its rolling stock or its global production lines.

The access point, according to Stadler, was a data exchange platform used with an unnamed supplier. The attackers authenticated using compromised login credentials. Stadler did not name the supplier, disclose when the intrusion occurred, specify the volume of data accessed, or say whether the credentials belonged to the supplier, Stadler, or another party with access to the platform.

A refusal without the usual leak-site pressure

Stadler said it would not pay the ransom. That position is notable because Everest did not appear to have listed the company on its data leak site at the time the incident became public, and the technical information had not appeared there.

That is not the usual extortion sequence. Ransomware and data-theft groups often list nonpaying victims on leak sites after an initial deadline passes, then use a second countdown to pressure the target before publishing stolen material. Victims that pay are typically removed from the site, while those that do not may see data released.

Stadler’s situation appears to have avoided the more visible phase of that process, at least so far. The company’s account also suggests the breach was contained to a third-party data channel rather than an intrusion into its internal network. That distinction matters for operators assessing blast radius, but it does not remove the commercial risk attached to exposed technical files.

The company did not say whether it reset credentials across the platform, changed supplier access controls, or brought in outside incident response support. It also did not disclose whether regulators, customers, or transportation authorities were notified.

Everest’s broader activity

Everest is a Russian-speaking cybercrime group active since around December 2020. The group has claimed attacks involving companies including Under Armour, Mailchimp, AT&T and Collins Aerospace.

The group has used both data-theft extortion without encryption and double-extortion tactics, where attackers combine stolen data with system encryption. It has also moved into initial access brokering and attempts to recruit corporate insiders, according to accounts of its activity.

For industrial companies, the Stadler incident fits a wider pattern: attackers do not need to penetrate production systems to create leverage. Supplier portals, shared engineering repositories and partner access tools can hold enough sensitive material to support a ransom demand, even when factories keep running and customer-facing operations appear normal.

This story draws on original reporting from The Register.

More from Policy

All Policy →