Stadler Rail Tells Ransomware Gang to Take a Hike on a CHF 10 Million Demand
Swiss train manufacturer Stadler Rail has knocked back a CHF 10 million ($12.3 million) ransom demand from the Everest ransomware group, and by all accounts got away with it relatively intact.
The breach didn't touch Stadler's own systems. Instead, attackers got in through a data exchange platform the company shared with an unnamed supplier, using stolen credentials to access technical files. No personal data was taken, no production lines were disrupted, and the company's rolling stock kept rolling.
By the standards of ransomware incidents, that's a pretty clean outcome.
What's genuinely strange here isn't that Stadler refused to pay. It's that the company hasn't shown up on Everest's data leak site. That's not how this normally plays out.
The standard ransomware shakedown goes like this: steal data, tell the victim, demand money, threaten to publish. If the deadline passes without payment, the victim gets posted publicly. Then comes a second countdown, a final chance to pay before the files go live. Victims who pay get scrubbed. Victims who don't get their data dumped.
Stadler refused, and still hasn't appeared. That combination is unusual enough to raise an eyebrow.
Everest has been running since around December 2020 and has claimed hits on some fairly recognisable names over the years, including Under Armour, AT&T, Mailchimp, and Collins Aerospace. Whether they're holding back Stadler's data for strategic reasons or simply have less than they're claiming is anyone's guess.
For now, Stadler appears to have called the bluff. Whether Everest proves them wrong remains to be seen.