Skip to content
feed: live
>_ 0dayNews
ransomware
● Breaking

Stadler Rail Refuses $12.3M Ransom from Everest

Stadler Rail refused a $12.3M ransom from the Everest group after a supplier data exchange platform was compromised in mid-July 2026.

Stadler Rail Refuses $12.3M Ransom from Everest
Photo: JoachimKohler-HB / Wikimedia Commons · CC BY-SA 4.0
airgap airgap · Published · 1 min read

Stadler Rail is not paying. The Swiss train manufacturer — 18,000 employees, $4.9 billion in annual revenue — confirmed this week that the Everest ransomware group breached a data exchange platform shared with one of its suppliers in mid-July 2026 and demanded 10 million Swiss francs (~$12.3 million USD). The company filed a criminal complaint with Thurgau cantonal police and stated it will “not pay any ransom under any circumstances.”

Production and core IT systems: unaffected throughout. Stadler says global operations continued normally.

What was accessed

The entry point was a third-party data exchange platform — supplier-shared infrastructure, not Stadler’s primary IT environment. The company characterizes the stolen material as technical information that is “not security relevant,” with “no relevant personal data stolen.” That assessment is Stadler’s own. Independent verification is not available at this time. Unconfirmed — treat accordingly.

Everest’s current posture

As of BleepingComputer’s publication, Everest had not publicly claimed the attack on its active extortion site. The group’s original dark web leak site was defaced in April 2025; it has since migrated to a new domain. Whether it publishes the stolen technical data is the live question.

Everest has operated since 2020 and has shifted steadily toward a pure data-theft extortion model — encryption is no longer central to their approach. Ransom refusals historically escalate to data dumps within weeks.

Prior incident

This is the second time Stadler has declined to engage with attackers. The company disclosed a separate malware infection and data theft in 2020, also without payment.

What to watch

Everest’s next move on its leak site. The unnamed supplier whose data exchange platform was the entry point. Whether Thurgau cantonal police or Swiss federal authorities escalate the case given the group’s cross-border infrastructure.

For context on how ransomware actors are shifting toward extortion-only models without encryption, see our coverage of Anubis’s claim against Coca-Cola’s Fairlife subsidiary.

Found this useful? Share it.