Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Everest ransomware group. Show all posts

Stadler Rail Rejects $12.3 Million Everest Ransomware Demand After Supplier Data Breach

Swiss rail manufacturer Stadler Rail has disclosed that the Everest ransomware group demanded approximately $12.3 million after gaining access to a data exchange platform used by one of the company’s suppliers.

The cybercriminal group has not publicly listed Stadler Rail as a victim. However, the company said it received an extortion letter from Everest demanding 10 million Swiss francs in exchange for not releasing the stolen information.

Stadler said it has refused to make any payment and has reported the incident to the Thurgau cantonal police.

"Stadler will not pay any ransom under any circumstances and is therefore not susceptible to extortion."

According to the company, the incident took place in mid-July and did not compromise Stadler's own IT infrastructure or disrupt its manufacturing operations. Production activities across its global facilities are continuing normally.

The company said the attackers obtained technical information from a supplier, but the material was not considered security-sensitive. Stadler also stated that the incident did not result in the theft of relevant personal information.

"No relevant personal data was stolen. Stadler's rail vehicles operating worldwide are not affected by the data theft. Stadler's global production continues as normal."

Stadler Rail is a major Swiss manufacturer with operations spanning locomotives, trams, metro systems, passenger trains and railway signaling equipment. The company serves rail operators internationally and has around 18,000 employees across eight production facilities and six engineering locations. Its annual revenue exceeds $4.9 billion.

Everest first emerged in 2020 as a ransomware operation but later shifted away from encrypting victims' networks. Instead, the group increasingly focused on stealing sensitive information and threatening organizations with public disclosure unless they agreed to pay a ransom.

The group has also previously operated as an initial access broker, selling compromised network access to other cybercriminals. In some cases, Everest has reportedly obtained stolen information from other attackers and used it to pressure victims for payment.

The ransomware operation currently uses a new leak site after its previous dark web platform was defaced in April 2025 with the message: "Don't do crime CRIME IS BAD xoxo from Prague." Stadler Rail has not been added to Everest's current extortion website at the time of the company's disclosure.

This is not Stadler's first reported cybersecurity incident. In 2020, an unidentified threat actor breached the company's IT environment, infected parts of its infrastructure with malware and extracted information from compromised systems. While the incident appeared consistent with a ransomware attack, Stadler did not officially confirm its nature at the time.