Swiss train maker Stadler refuses Everest $12 million ransomware demand
Swiss train manufacturer Stadler Rail said it will not pay a $12.3 million ransom after cybercriminals stole technical data from a supplier's file-sharing platform.
According to the company’s statement on Tuesday, the breach, which occurred in mid-July, did not affect its own systems, and all production sites remain fully operational.
The stolen information consisted of technical documents belonging to a third-party supplier and was obtained after credentials for the data exchange platform were compromised. Stadler said it did not lose any of its own data, no relevant personal information was stolen, and the breach has no impact on trains operating worldwide.
The company said the ransomware group Everest claimed responsibility for the incident in an extortion letter demanding 10 million Swiss francs. Stadler said it has filed a criminal complaint and will not negotiate with the hackers.
"Under no circumstances will Stadler pay a ransom and therefore cannot be extorted," the company said.
Switzerland-based Stadler is one of Europe's largest rail equipment manufacturers, supplying trains, trams, metro cars, and locomotives to rail operators around the world. The publicly traded company employs about 18,000 people and generates more than $4.9 billion in annual revenue.
Stadler did not say whether the attackers had begun releasing any of the stolen supplier data. As of Thursday, Everest had not listed the company on its dark web leak site. Stadler declined to provide additional comment on the incident.
This is the second known extortion attempt against Stadler in recent years. In 2020, unknown attackers infiltrated some of the company's systems, stole internal data, and demanded roughly $6 million in bitcoin. After Stadler refused to pay, the attackers published samples of the stolen files, which reportedly included financial and administrative documents. The company stood by its decision not to negotiate even after the data was leaked.
Everest is a Russian-speaking ransomware and extortion group that has been active since at least 2020 and has targeted organizations in critical infrastructure sectors, including energy, transportation, and telecommunications.
Last year, the group claimed responsibility for a cyberattack involving an external file transfer system used by Sweden's state-owned electricity grid operator, Svenska kraftnät, although the incident did not disrupt power supplies.
More recently, Everest claimed responsibility for a breach involving a contractor for Japanese automaker Nissan. Nissan said attackers had compromised systems operated by the third-party vendor but found no evidence that its own customer data had been accessed.
Cybercrime experts advise that paying a ransom can often lead to further hassles from attackers. Researchers at cybersecurity company Proofpoint reported Wednesday that a survey of 953 organizations found 54 percent had paid ransoms, and of that portion, more than one-third faced a second extortion demand.
References in this story
- Cybervorfall | Stadler www.stadlerrail.com Lesen Sie unsere neuesten Medienmitteilungen, um über die jüngsten Ankündigungen, Produkteinführungen und Unternehmensnachrichten auf dem neusten Stand zu bleiben.
- Sweden’s power grid operator confirms data breach claimed by ransomware gang therecord.media The utility responsible for operating Sweden's power grid is investigating a data breach after a ransomware group threatened to leak hundreds of gigabytes of purportedly stolen internal data.
- Nissan says stolen data came from third-party vendor after hacking group claims breach therecord.media A hacking group claimed this week to have breached the file-transfer system used by a company that offers services to Nissan and Infiniti dealerships across North America. Nissan said there was no indication "customer…
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your business.
- Daryna Antoniuk (@darynant.bsky.social) bsky.app Cybersecurity Reporter at Recorded Future News. Ex at The Kyiv Independent/Forbes/The Kyiv Post 📍Kyiv, Ukraine



