Stadler Rail Rejects Everest’s $12.3 Million Ransom Demand Following Data Breach

Published:

spot_img

Swiss train manufacturer Stadler Rail has announced it will not pay a $12.3 million ransom demanded by the ransomware group Everest, following a data breach that occurred in mid-July. The breach involved the theft of technical documents from a third-party supplier’s file-sharing platform, but Stadler confirmed that its own systems were not affected and that all production sites remain operational. The company has filed a criminal complaint and stated it will not negotiate with the hackers. For further details, see the report by The Record.

Details of the Breach

The stolen data consisted of technical documents belonging to a third-party supplier, obtained after the credentials for the data exchange platform were compromised. Stadler emphasized that no personal information was stolen and that the breach has no impact on trains operating worldwide.

Response to Ransom Demand

Everest, the group responsible for the attack, issued an extortion letter demanding 10 million Swiss francs. In its statement, Stadler declared, “Under no circumstances will Stadler pay a ransom and therefore cannot be extorted.” This incident marks the second known extortion attempt against the company, following a similar attack in 2020.

Background on Everest

Everest is a Russian-speaking ransomware and extortion group that has been active since at least 2020, targeting organizations in critical infrastructure sectors such as energy, transportation, and telecommunications. The group previously claimed responsibility for a cyberattack on Sweden’s state-owned electricity grid operator and a breach involving a contractor for Nissan.

As of the latest updates, it remains unclear whether Everest has begun releasing any of the stolen supplier data, and the group has not listed Stadler on its dark web leak site.

spot_img

Related articles

Recent articles

Ransomware Landscape Shifts as Active Groups Rise and Payment Rates Decline in Q2 2026

The ransomware landscape is undergoing a notable transformation, as highlighted in the latest State of Ransomware Q2 2026 report from Check Point Research. While...

AMD Security Advisory AV26-813 Warns of Vulnerabilities in Multiple Products

AMD Security Advisory AV26-813: Vulnerabilities Identified in Multiple Products On August 11, 2026, AMD disclosed vulnerabilities affecting several of its products, as detailed in the...

New Evooo1Bot variant enhances Mirai botnet with stealth and advanced capabilities

Researchers at FortiGuard Labs have identified a new variant of the Mirai botnet, named Evooo1Bot, which has been actively exploiting vulnerabilities in internet-facing hardware...

AdvanzaTech Appointed Official AnyDesk Distributor for UAE and Middle East

AdvanzaTech, a Dubai-based cybersecurity and enterprise software distributor, has been appointed as the official distributor for AnyDesk in the UAE and the broader Middle...