Swiss rail automobile producer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a knowledge trade platform shared with considered one of its suppliers.
The menace actor has not publicly claimed the assault, however the Swiss firm says that it acquired an extortion letter from Everest ransomware asking for a ransom of 10 million Swiss francs.
The corporate responded by saying that it’ll not pay the menace actor and filed a legal grievance with the Thurgau cantonal police.
“Stadler is not going to pay any ransom beneath any circumstances and is due to this fact not prone to extortion.”
Stadler Rail is a big, multinational Swiss practice producer that builds locomotives, trams, metro trains, passenger trains, and railway signaling programs.
The corporate provides rail operators worldwide, employs 18,000 folks working in 8 manufacturing services and 6 engineering websites, and has an annual income of over $4.9 billion.
Stadler stated that the incident occurred in mid-July and neither its IT programs nor its manufacturing operations had been impacted, and proceed as regular globally.
In line with the corporate’s disclosure, the hackers stole from a provider solely technical data that isn’t safety related.
“No related private knowledge was stolen. Stadler’s rail automobiles working worldwide will not be affected by the information theft. Stadler’s world manufacturing continues as regular.”
Everest is a menace group that emerged in 2020 as a ransomware operation however deserted the community encryption tactic in favor of information theft. The gang now threatens victims with leaking the stolen knowledge until a ransom is paid.
Up to now, Everest bought its entry to the networks it breached to different menace actors, performing as an preliminary entry dealer. Generally, the hackers acquired knowledge stolen by different menace actors to conduct their very own extortion campaigns.
At present, the Everest ransomware gang is working a brand new area, after its authentic darkish internet leak website was defaced in April 2025 with the message: “Do not do crime CRIME IS BAD xoxo from Prague.” Stadler Rail just isn’t but listed on the gang’s extortion website.
In 2020, Stadler suffered a cybersecurity incident the place an unknown hacking group infiltrated its IT programs, contaminated elements of its infrastructure with malware, and stole knowledge from compromised gadgets.
The case gave the impression to be a ransomware assault, although Stadler didn’t affirm it on the time.
Safety groups log 54% of profitable assaults and alert on simply 14%. The remaining transfer by means of your setting unseen.
The Picus whitepaper exhibits how breach and assault simulation exams your SIEM and EDR guidelines so threats cease slipping by detection.


