2 Remove Virus

Stadler Rejects $12.3 Million Ransom After Supplier Platform Breach

Swiss rail manufacturer Stadler has refused to pay a ransom of 10 million Swiss francs, approximately $12.3 million, following the theft of technical information from a platform shared with one of its suppliers.

 

 

The Everest cybercrime group claimed responsibility for the intrusion in an extortion letter sent to the company. Stadler said it would not pay the requested amount and has filed a criminal complaint with the cantonal police in Thurgau, Switzerland.

According to the manufacturer, the attackers obtained compromised login credentials for a data-exchange platform used by Stadler and an unnamed supplier. Those credentials allowed unauthorized access to technical material belonging to the supplier.

Stadler said the attackers did not compromise its internal IT infrastructure. The company also stated that its global production operations continued normally throughout the incident.

No relevant personal information was stolen, according to Stadler. The company described the accessed files as technical supplier data that did not affect railway safety or the operation of Stadler vehicles already in service.

The incident therefore did not disrupt the production of trains, trams, locomotives, or other rail equipment. Stadler also said that rail vehicles operating around the world were not affected by the stolen information.

Everest demanded the payment after claiming responsibility for the data theft. Stadler publicly rejected the demand, stating that it would not pay a ransom under any circumstances.

The case appears to be a data-theft extortion attempt rather than an attack that encrypted Stadler’s systems. In this type of operation, criminals steal files and threaten to publish or otherwise misuse them unless the targeted organization pays.

As of July 24, Stadler had not appeared on Everest’s public data-leak site, according to reporting that monitored the group’s listings. No publication of the stolen supplier material had been confirmed at that time.

The absence of a listing does not establish what Everest intends to do with the information. Stadler has not confirmed that the attackers deleted the files, and the company has not reported paying or negotiating with the group.

The company’s disclosure identified Everest because the group named itself in the extortion message. That attribution is based on the attackers’ own claim rather than a publicly disclosed conclusion from law enforcement or an independent forensic investigation.

Everest has operated as a data-theft and extortion group, threatening to expose information taken from compromised organizations. It has also previously claimed attacks against companies in the energy, telecommunications, retail, and transportation sectors.

Claims published by ransomware and extortion groups are not proof that they accessed all the systems or information they describe. In Stadler’s case, the company confirmed only the theft of technical supplier data through compromised credentials for the shared exchange platform.

Stadler said the incident remained limited to that external access route. Its own systems were not breached, its production facilities remained operational, and it found no effect on the safety or functioning of its rail vehicles.

The company has submitted a criminal complaint to the Thurgau cantonal police. No arrests, formal charges, or further findings from the police investigation had been announced in the information available at the time of publication.