Swiss Rail Giant Stadler Rejects $12.3M Ransom Demand After Cyberattack
Swiss rail vehicle manufacturer **Stadler Rail** has publicly refused to pay a $12.3 million (10 million Swiss francs) ransom demanded by the **Everest** ransomware gang. The attack, which occurred in mid-July, reportedly targeted a data exchange platform shared with one of its suppliers, leading to the theft of technical, non-security-relevant information.
Swiss train manufacturer **Stadler Rail** has taken a firm stance against cyber extortion, rejecting a $12.3 million ransom demand from the **Everest** ransomware group. The company confirmed it received an extortion letter after **Everest** breached a data exchange platform used with a supplier.
### Incident Details and Company Response
**Stadler Rail** promptly filed a criminal complaint with the Thurgau cantonal police, declaring its unwavering policy: "Stadler will not pay any ransom under any circumstances and is therefore not susceptible to extortion."
Despite the data theft, **Stadler** stated that its internal IT systems and global production operations remain unaffected and are functioning normally. The company, a multinational giant employing 18,000 people and generating over $4.9 billion in annual revenue, clarified that the stolen data was technical in nature and not security-relevant. Crucially, no personal data was compromised, and the operational integrity of its rail vehicles worldwide is secure.
### The Evolution of Everest Ransomware
**Everest** emerged in 2020, initially operating as a traditional ransomware group. However, it has since shifted its tactics, abandoning network encryption in favor of pure data exfiltration and extortion. The group now threatens to leak stolen data if ransoms are not paid.
Historically, **Everest** has also functioned as an initial access broker (IAB), selling network access to other threat actors. In some instances, it has even acquired data stolen by other groups to conduct its own extortion campaigns.
### Current Status and Past Incidents
Currently, the **Everest** gang operates from a new domain, following the defacement of its original dark web leak site in April 2025 with the message: "Don't do crime CRIME IS BAD xoxo from Prague." As of now, **Stadler Rail** is not listed on the group's extortion site.
This isn't **Stadler's** first encounter with cyber threats. In 2020, the company experienced another cybersecurity incident where an unknown hacking group infiltrated its IT systems, deployed malware, and exfiltrated data. While the incident bore the hallmarks of a ransomware attack, **Stadler** did not confirm it at the time.