Swiss train manufacturer Stadler Rail refused to pay a $12.3 million ransom after the Everest extortion gang breached a supplier data exchange platform in mid-July 2026, the company confirmed. Stadler filed a criminal complaint with the Thurgau cantonal police.
Quick Summary – TLDR:
- Stadler Rail rejected a $12.3 million ransom demand from the Everest gang and said it will not negotiate under any circumstances.
- Everest stole technical data after compromising login credentials for a platform shared with one of Stadler’s suppliers.
- Stadler said its own IT systems, production lines, and rail vehicles worldwide were not affected by the breach.
- Stadler filed a criminal complaint with cantonal police in Thurgau, Switzerland, where the company is headquartered.
- Everest dropped file encryption in 2020 and now runs pure data-theft extortion instead of locking victims out.
What Happened?
The Everest ransomware gang demanded 10 million Swiss francs, roughly $12.3 million, in an extortion letter sent to Stadler after intruders reached a shared data exchange platform, according to the company’s public disclosure. The attackers obtained login credentials tied to one of Stadler’s suppliers and used them to access specific technical information held on that platform.
Stadler said the intruders never entered its own network. Its internal systems kept running normally, and the manufacturer, which employs 18,000 people across 8 production facilities and reports annual revenue above $4.9 billion, said global production continued without interruption.
The company drew a hard line on payment. “Stadler will not pay any ransom under any circumstances and is therefore not susceptible to extortion,” the manufacturer said, confirming it had filed a criminal complaint with police in Thurgau.
Swiss rail manufacturer Stadler Rail rejected a $12.3 million ransom demand from the Everest ransomware gang after hackers breached a supplier’s shared data exchange platform and stole internal technical files. Stadler says no personal data was taken and its own IT and production…
— Xavier Rivera (@XavierRiveraX) July 22, 2026
Technical Data Taken, No Personal Records
Stadler described the stolen files as technical material with no bearing on railway safety. “No relevant personal data was stolen. Stadler’s rail vehicles operating worldwide are not affected by the data theft. Stadler’s global production continues as normal,” the company said.
The distinction shapes the incident’s scope. Because the breach touched a supplier’s exchange platform rather than Stadler’s production, corporate, or onboard train systems, the manufacturer said no vehicles in service face a safety risk.
Several details stay unresolved. Stadler has not named the affected supplier, quantified how much technical data the attackers pulled, or said whether any of it has surfaced. Everest has not yet listed Stadler on its leak site, and the gang has not publicly claimed the attack, so it is unclear whether it plans to publish the files or is still applying pressure privately.
Who Is Everest?
Everest surfaced in 2020 as a conventional ransomware crew before abandoning file encryption in favor of straight data theft extortion. The gang steals files and threatens to leak them unless a victim pays.
Everest has also operated as an initial access broker, selling footholds in breached networks to other criminals and, at times, repackaging data stolen by other actors into its own extortion campaigns. The group moved to a new dark web domain after its original leak site was defaced in April 2025 with the message: “Don’t do crime CRIME IS BAD xoxo from Prague.”
Implications for Supply Chain Security
The breach fits a pattern security teams increasingly track: attackers skip a hardened target by compromising a weaker partner. Stadler’s own network held, yet a supplier’s stolen credentials still exposed company data, a reminder that third party access widens the attack surface beyond what any single firm directly controls.
This is not Stadler’s first incident. In 2020, an unidentified group infiltrated its IT systems, planted malware, and stole data before attempting to blackmail the company. The earlier attack reached Stadler directly. The latest one landed through a supplier, which is why the manufacturer could keep its production and trains out of the blast radius this time.
SQ Magazine’s Takeaway
Stadler’s refusal strips away the immediate leverage Everest hoped to gain, though it does nothing to undo the theft itself. The stance lines up with law enforcement guidance that discourages ransom payments, which fund further attacks and rarely guarantee that stolen data is deleted. For a manufacturer whose safety critical products were untouched, that calculation is far easier than it is for victims staring down an operational shutdown.
What comes next depends on Everest. The gang could publish the technical files, keep pressing for payment, or move on, and Stadler’s absence from the leak site is the signal to watch in the coming weeks. Organizations that run shared data exchange platforms with suppliers can reduce their exposure by rotating credentials for third-party portals, enforcing multi-factor authentication on those systems, and auditing which partners still hold access to sensitive technical files. The Stadler case shows the practical value of network segmentation, since keeping supplier platforms separate from core systems is what contained the damage here.