Stadler says Everest ransomware gang stole supplier-shared data and demanded $12.3 million

Swiss rail manufacturer Stadler says the Everest extortion group breached a data exchange platform shared with one of its suppliers and demanded about $12.3 million not to leak stolen data. Stadler says the incident happened in mid-July 2026, that its own IT systems and production were not disrupted, and that the attackers took technical information from the supplier side rather than security-relevant or personal data. The company filed a criminal complaint and says it will not pay.
Why it matters: This is a real supply-chain-linked extortion event affecting a major transportation manufacturer, even though Stadler says operations and rail vehicles were not impacted. Organizations that share files or platforms with suppliers should review third-party access, data exchange security, and exposure of technical documents.

Sources

In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws
SecurityWeek News 2026.07.24 95% relevant
This article summarizes the same Stadler event, including that Everest demanded about 10 million Swiss francs after stealing technical information from a supplier-shared data exchange platform, without affecting Stadler’s production or core IT systems.
Swiss train maker tells ransomware crooks to get off at the next stop
2026.07.23 96% relevant
This article is a direct report on the same Stadler/Everest incident and adds detail that the attackers used compromised login credentials to access a supplier data exchange platform, that Stadler’s own IT systems were not breached, and that the stolen material was limited to technical supplier information.
Swiss train maker Stadler refuses Everest $12 million ransomware demand
2026.07.22 98% relevant
This article is a direct update on the same incident, adding Stadler's public refusal to pay, confirmation that compromised credentials to a supplier data-exchange platform were used, and that Stadler says its own systems, personal data, and train operations were not affected.
Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
Bill Toulas 2026.07.22 100% relevant
This article appears to be the first concrete report of this specific mid-July 2026 Stadler extortion incident involving Everest and a supplier-shared data exchange platform.
← Back to all stories