Swiss rail vehicle manufacturer Stadler Rail announced it rejected a ransom demand of 10 million Swiss francs (approximately $12.3 million USD) from the Everest ransomware gang. The demand followed a breach of a data exchange platform shared with one of Stadler's suppliers. The company stated it would not pay any ransom and filed a criminal complaint with local police.
Stadler reported that the incident occurred in mid-July but did not affect its IT systems or global production operations, which continue as normal. The company confirmed that no relevant personal data was stolen, and the stolen information consisted only of technical data not considered security-relevant. Stadler's rail vehicles operating worldwide were not affected by the data theft.
Everest is a threat group that emerged in 2020, initially as a ransomware operation. The group later shifted its tactics to focus on data theft and extortion, abandoning network encryption. Everest threatens victims with data leaks if a ransom is not paid. The gang has also operated as an initial access broker, selling access to breached networks to other threat actors.
This is not Stadler's first encounter with cyberattacks. In 2020, the company experienced a cybersecurity incident where an unknown hacking group infiltrated its IT systems, infected parts of its infrastructure with malware, and stole data. While Stadler did not confirm it at the time, that incident also appeared to be a ransomware attack.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Swiss rail vehicle manufacturer Stadler Rail rejected a $12.3 million ransom demand from the Everest ransomware gang following a data breach on a platform shared with a supplier. The company reported no impact on its IT systems or production operations, and stated only non-security-relevant technical information was stolen, demonstrating a firm stance against cyber extortion.