{"id":107086,"date":"2026-07-23T09:47:10","date_gmt":"2026-07-23T09:47:10","guid":{"rendered":"https:\/\/www.europesays.com\/ch\/107086\/"},"modified":"2026-07-23T09:47:10","modified_gmt":"2026-07-23T09:47:10","slug":"swiss-rail-manufacturer-stadler-refuses-to-pay-12-3-million-ransom-after-cyberattack","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ch\/107086\/","title":{"rendered":"Swiss rail manufacturer Stadler refuses to pay $12.3 million ransom after cyberattack"},"content":{"rendered":"<p>Cybercriminal group Everest is demanding 10 million Swiss francs ($12.3 million) from Swiss rail vehicle manufacturer Stadler after breaching a data exchange platform shared with one of its suppliers through <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/02\/18\/identity-based-cyberattacks-compromise\/\" rel=\"nofollow noopener\" target=\"_blank\">compromised credentials<\/a>.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ch\/wp-content\/uploads\/2026\/07\/stadler-650.webp\" class=\"aligncenter\" alt=\"Stadler ransom demand\" title=\"Stadler\"\/><\/p>\n<p>Stadler operates 16 production and component plants and eight engineering centers, backed by a global service network of more than 95 locations, and employs over 17,100 people from over 75 countries.<\/p>\n<p>The Swiss company confirmed it received an extortion letter in which the Everest ransomware gang claimed responsibility and demanded 10 million Swiss francs.<\/p>\n<p>\u201cUnder no circumstances will Stadler pay a ransom,\u201d the manufacturer said, adding that it is therefore not susceptible to extortion.<\/p>\n<p>The company has filed a criminal complaint with the Thurgau Cantonal Police.<\/p>\n<p>According to the company\u2019s <a href=\"https:\/\/www.stadlerrail.com\/en\/media\/media-releases\/cybervorfall\" target=\"_blank\" rel=\"nofollow noopener\">disclosure<\/a>, the incident occurred in mid-July and did not affect its IT systems or production operations. The company added that the attackers accessed only technical information belonging to a supplier that is not safety-relevant, with no relevant personal data stolen and no impact on its rail vehicles operating worldwide.<\/p>\n<p>Everest emerged in December 2020 with a focus on data exfiltration without encryption, primarily targeting Canadian organizations.<\/p>\n<p>Since then, it has evolved into a hybrid operation, acting as both a ransomware group and an initial access broker that sells stolen network credentials to other criminals, while also running a recruitment scheme that pays company insiders for direct access to their employers\u2019 networks.<\/p>\n<p>Everest has also claimed responsibility for disruptions at several major European <a href=\"https:\/\/www.bitdefender.com\/en-us\/blog\/hotforsecurity\/everest-ransomware-group-claims-theft-of-1-5-million-passenger-records-from-dublin-airport\" target=\"_blank\" rel=\"nofollow noopener\">airports<\/a>, including Heathrow, Brussels, Berlin, Dublin, and Cork.<\/p>\n<p>Rail industry digitization is likely to make the sector a more <a href=\"https:\/\/www.helpnetsecurity.com\/2025\/09\/09\/railway-systems-cybersecurity\/\" rel=\"nofollow noopener\" target=\"_blank\">frequent target<\/a> for criminal groups in the years ahead.<\/p>\n","protected":false},"excerpt":{"rendered":"Cybercriminal group Everest is demanding 10 million Swiss francs ($12.3 million) from Swiss rail vehicle manufacturer Stadler after&hellip;\n","protected":false},"author":2,"featured_media":107087,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[4],"tags":[2588,52348,787,2074,41,17],"class_list":["post-107086","post","type-post","status-publish","format-standard","has-post-thumbnail","category-switzerland","tag-critical-infrastructure","tag-data-breach","tag-eu","tag-ransomware","tag-swiss","tag-switzerland"],"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@ch\/116968662405363014","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ch\/wp-json\/wp\/v2\/posts\/107086","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ch\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ch\/wp-json\/wp\/v2\/comments?post=107086"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ch\/wp-json\/wp\/v2\/posts\/107086\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ch\/wp-json\/wp\/v2\/media\/107087"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ch\/wp-json\/wp\/v2\/media?parent=107086"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ch\/wp-json\/wp\/v2\/categories?post=107086"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ch\/wp-json\/wp\/v2\/tags?post=107086"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}