Everest Ransomware Gang Demands $12.3M from Swiss Rail Manufacturer Stadler
Swiss rail giant Stadler has refused a $12.3 million ransom demand from the Everest ransomware group following a cyberattack that compromised a data exchange platform shared with a supplier.

Swiss rail vehicle manufacturer Stadler Rail has publicly confirmed it was targeted by the Everest ransomware gang, which demanded approximately $12.3 million (10 million Swiss francs) after breaching a data exchange platform shared with one of its suppliers. The company has firmly rejected the ransom demand and has initiated a criminal complaint with the Thurgau cantonal police.
In a statement, Stadler emphasized its unwavering stance against paying ransoms, declaring, "Stadler will not pay any ransom under any circumstances and is therefore not susceptible to extortion." The multinational manufacturer, known for producing locomotives, trams, and passenger trains for global operators, employs 18,000 people and generates over $4.9 billion in annual revenue.
The incident, which occurred in mid-July, did not impact Stadler's IT systems or global production operations, which continue to function normally. According to the company's disclosure, the attackers stole only technical information from a supplier, which is not considered security-relevant. Stadler assured that no relevant personal data was compromised and that its worldwide rail vehicle operations remain unaffected by the data theft.
The Everest ransomware group, which emerged in 2020, has shifted its tactics from network encryption to data theft and extortion. The gang typically threatens victims with the public release of stolen data unless a ransom is paid. In some instances, Everest has also acted as an initial access broker, selling network access to other threat actors, or has leveraged data stolen by others for its own extortion campaigns.
This incident marks not the first cybersecurity challenge for Stadler. In 2020, the company experienced a separate incident where an unknown hacking group infiltrated its IT systems, deployed malware, and exfiltrated data. While that case bore similarities to a ransomware attack, Stadler did not confirm the specific nature of the threat at the time.
The Everest gang has recently operated from a new domain, following the defacement of its original dark web leak site in April 2025. Stadler Rail has not yet been listed on the gang's current extortion site, suggesting the attackers may still be in the early stages of their campaign or that Stadler's refusal to pay has preempted public exposure.
This attack on Stadler highlights the persistent threat posed by ransomware groups targeting supply chains. By compromising shared platforms, attackers can gain access to multiple organizations, amplifying their potential impact and leverage. The company's swift refusal to pay and its engagement with law enforcement demonstrate a proactive approach to mitigating the fallout from such incidents.
The incident serves as a reminder for organizations to rigorously vet their suppliers' security postures and to implement robust data protection measures, especially for shared platforms. The focus remains on preventing breaches and ensuring business continuity even when targeted by sophisticated cybercriminal operations.