407/69 Friday, July 24, 2026
Stadler Rail, a major Swiss rail vehicle manufacturer, disclosed that it received a ransom demand from the Everest ransomware group for 10 million Swiss francs, or approximately USD 12.3 million, after a cyberattack affected a data exchange platform used with one of the company’s suppliers. Stadler stated that it would not pay the ransom under any circumstances and has filed a criminal complaint with the police. Stadler Rail manufactures locomotives, trams, metro trains, passenger trains, and railway signaling systems.
The company stated that the incident occurred in mid-July. Stadler’s IT systems and production processes were not affected, and global production continues to operate as normal. According to information disclosed by the company, the attackers stole data from one supplier. The stolen data consisted of technical information that was not related to system safety or security, and no sensitive personal information was stolen. Stadler also confirmed that its trains and rail vehicles in operation worldwide were not affected by the data breach.
Everest is a threat group that first appeared in 2020 in ransomware operations but later shifted from encrypting systems to stealing data and threatening to publish it if victims do not pay. In some cases, the group has sold access to compromised networks to other attackers as an Initial Access Broker or used data stolen by other groups to extort victims. Although Everest was identified as the group that sent the ransom demand, it had not claimed responsibility for the Stadler incident on its extortion site at the time of reporting. Stadler previously experienced a cybersecurity incident in 2020, when unknown hackers breached its IT systems, deployed malware in parts of its infrastructure, and stole data from compromised devices.
