Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Stadler Rail Refuses $12.3 Million Extortion Demand Following Cyber Incident

Stadler Rail Refuses $12.3 Million Extortion Demand Following Cyber Incident

By: Jordan Vector Cybersecurity Expert

Last updated: July 23, 2026

Human Written
Stadler Rail Refuses $12.3 Million Extortion Demand Following Cyber Incident
  • Swiss company Stadler Rail has refused to pay a ransom of $12.3 million demanded from the cybercriminal group Everest.

  • The attackers managed to get access to a platform for file exchange using compromised login and have stolen some non-classified technical information of one of the third-party suppliers.

  • The internal IT networks of Stadler, global factory operations, and passenger rail vehicles remained completely unaffected, prompting the firm to file a criminal police complaint.

Stadler Rail, a railway manufacturing company based in Switzerland, indicated recently that it has fought off an extortion attempt of millions of dollars after experiencing a cybercrime attack.

The hackers targeted a file sharing site the company uses for online file exchange with a third-party supplier. They made a ransom demand of 10 million Swiss francs, which is more than 12.3 million US dollars.

Stadler leadership immediately refused to negotiate with the extortion group; company executives declared that the organization would not pay money to cybercriminals under any circumstances. Official representatives quickly filed a formal criminal complaint with cantonal police authorities in Thurgau, Switzerland.

The intrusion occurred during mid-July without disrupting rail operations across international markets. Company administrators confirmed that internal corporate systems remained completely uncompromised throughout the security incident. Onboard train equipment and signaling networks operating across global transit systems faced zero safety hazards or operational interruptions.

Details of the Shared Data Exchange Platform Intrusion

The perpetrators acquired access to the external platform for file sharing using compromised credentials. The accessed credentials belonged to a third-party supplier rather than Stadler Rail itself. The intruders used these credentials to enter the shared environment and download restricted technical files.

The stolen material consisted strictly of technical documentation owned by the partner vendor. The downloaded files did not include safety-related or confidential corporate information or sensitive data on employees. The intruders could not get into the central electronic system of Stadler and hence corporate databases and internal communication were not affected.

Stadler Rail is one of the major companies manufacturing rail technology in Europe. The multinational corporation engages in the production of various railways including electric locomotives, regular passenger carriages, underground metro trains, trams, and railway control systems. The company has 8 major manufacturing plants and 6 engineering research plants around the globe.

The total number of employees of the company is more than 18,000 people and the revenue is about $4.9 billion. Operating at such a scale makes it necessary to ensure network security both within the company and that of its suppliers. The strict network isolation protocols of the firm kept the supplier breach contained within the external portal.

Factory assembly lines continue to produce rolling stock without operational delays. Global rail operators using Stadler trains continue running scheduled passenger services safely. By refusing to engage with extortionists, the firm reinforced its long-standing corporate policy against paying criminal ransoms.

Examining the Everest Ransomware Gang Operational Shift

The extortion letter came from a cybercrime syndicate known as the Everest ransomware group, this Russian-speaking syndicate first emerged in the cyber threat landscape around 2020. The group initially operated as a standard ransomware organization that encrypted victim networks using malicious code.

Over recent years, the gang abandoned system encryption tactics in favor of direct data theft. Modern extortion groups often skip network lockers because encrypting files triggers automated security responses quickly. The syndicate now focuses on stealing confidential files silently and threatening public disclosure unless victims pay ransoms.

The tactic of threatening data leaks has led to criminal charges in other cases, a California man has been charged with hacking a business and threatening a data leak.

In addition to direct extortion, Everest historically operated as an initial access broker. The group breached corporate perimeters and sold administrative network access to other criminal actors on dark web forums. The gang also purchased data stolen by secondary threat groups to conduct independent extortion campaigns against corporate victims.

This group has attacked prominent companies from different sectors in the past – such as the automotive, aviation, and energy industries. The victims were big names such as BMW, Collins Aerospace, and Svenska Kraftnät from Sweden. Most recently, the gang attacked a subcontractor of the Japanese automobile company Nissan to obtain sensitive supply chain information.

The group experienced internal disruptions when vigilantes defaced its original dark web leak site in April this year. The unknown hackers left a taunting message telling the cybercriminals that crime is bad. Everest subsequently launched a new dark web domain to post stolen corporate records. The syndicate has not yet added Stadler Rail to its new extortion site.

Previous Cyber Incidents and Growing Supply Chain Security Risks

This latest attempt to extort money from the company marks the second serious attack faced by Stadler Rail in the last few years. Back in 2020, an unknown cybercriminal group hacked the IT infrastructure of Stadler Rail and used advanced malware to penetrate its systems. The hackers stole important company documents and financial records and asked the company for $6 million in ransom in Bitcoin.

In the former attack in 2020, Stadler refused to comply with the demands of the hackers. This resulted in them going public and leaking some data stolen from the company on the internet. Stadler showed its determination to stay true to its principles, establishing a strong anti-extortion policy.

The recent attack gives evidence to the fact that supply chain security risks are becoming more important and serious nowadays. Large companies now use advanced perimeter defense tools that make them less vulnerable; hence the attackers target their partners in the supply chain with lower security standards that are easier to hack. Criminals use different means to bypass corporate firewalls indirectly, such as online tools, remote access portals, and supplier accounts.

Cybersecurity specialists stress the need to manage third-party vendor risks for critical manufacturing sectors. Organizations must enforce strict multi-factor authentication across all external file transfer systems. Companies should also isolate shared vendor platforms from core operational technology networks to restrict potential lateral movement.

The experience of Stadler proves the value of robust network segmentation during supply chain incidents. By keeping supplier file systems separate from main production environments, the company prevented widespread operational downtime. The decisive law enforcement reporting of the firm sets a clear standard for handling digital extortion in the transportation industry.

Share this article

About the Author

Jordan Vector

Jordan Vector

Cybersecurity Expert

Jordan is a security researcher and advocate who focuses on making privacy practical. Whether he's explaining how to harden a browser or reporting on the latest surveillance disclosures, his goal is to equip readers with knowledge they can use immediately. Jordan believes that true security begins with understanding the digital landscape.

Comments (0)

No comments.