Swiss rail manufacturer Stadler says the Everest extortion group breached a data exchange platform shared with one of its suppliers and demanded about $12.3 million not to leak stolen data. Stadler says the incident happened in mid-July 2026, that its own IT systems and production were not disrupted, and that the attackers took technical information from the supplier side rather than security-relevant or personal data. The company filed a criminal complaint and says it will not pay.
Why it matters: This is a real supply-chain-linked extortion event affecting a major transportation manufacturer, even though Stadler says operations and rail vehicles were not impacted. Organizations that share files or platforms with suppliers should review third-party access, data exchange security, and exposure of technical documents.
SecurityWeek News
2026.07.24
95% relevant
This article summarizes the same Stadler event, including that Everest demanded about 10 million Swiss francs after stealing technical information from a supplier-shared data exchange platform, without affecting Stadler’s production or core IT systems.
2026.07.23
96% relevant
This article is a direct report on the same Stadler/Everest incident and adds detail that the attackers used compromised login credentials to access a supplier data exchange platform, that Stadler’s own IT systems were not breached, and that the stolen material was limited to technical supplier information.
2026.07.22
98% relevant
This article is a direct update on the same incident, adding Stadler's public refusal to pay, confirmation that compromised credentials to a supplier data-exchange platform were used, and that Stadler says its own systems, personal data, and train operations were not affected.
Bill Toulas
2026.07.22
100% relevant
This article appears to be the first concrete report of this specific mid-July 2026 Stadler extortion incident involving Everest and a supplier-shared data exchange platform.
← Back to all stories