Swiss train manufacturer Stadler Rail has confirmed it refused a CHF 10 million (approximately $12.3 million USD) ransom demand from the Everest ransomware group following a cybersecurity incident. The company stated that its own IT systems were not compromised and remained intact, and that the breach was limited to technical information accessed through a data exchange platform used with an unnamed supplier.
According to Stadler, the attackers gained access to the platform using compromised login credentials. The company emphasized that "no security-relevant data" was affected, and "no relevant personal data was stolen." Furthermore, the incident had no impact on the functioning of its rolling stock, which includes trains and tram carriages, or its global production lines.
The Everest ransomware gang, a Russian-speaking cybercrime group active since December 2020, typically follows a playbook of notifying victims of data theft, issuing a ransom demand, and threatening to leak data if payment is not made. Organizations that refuse to pay or miss deadlines are usually listed on the gang's data leak site (DLS).
However, Stadler's situation presents an unusual deviation from this pattern. Despite the company's outright refusal to pay the ransom, Stadler does not currently appear on Everest's DLS, nor has the allegedly stolen technical data been leaked. This absence is atypical for a victim that has publicly refused an extortion demand.
Everest has a history of engaging in both encryptionless extortion and double extortion, where data is both encrypted and threatened with public release. The group has also expanded its operations into initial access brokering and recruiting corporate insiders. Previous organizations claimed to have been targeted by Everest include Under Armour, Mailchimp, AT&T, and Collins Aerospace.






