← BACK TO FEED
ransomwareStadler RailEverestcybercrimesupply chain security

Stadler Rail Tells Ransomware Gang to Take a Hike on a CHF 10 Million Demand

Swiss rail manufacturer Stadler Rail refused a CHF 10 million ransom demand from the Everest ransomware gang after attackers accessed technical data from a supplier via a shared data exchange platform using compromised credentials. The company stated that no personal or security-relevant data was affected and that its own IT systems remained fully intact. Unusually, Stadler has not appeared on Everest's data leak site despite refusing to pay, which departs from the typical ransomware extortion playbook.

Swiss train manufacturer Stadler Rail has knocked back a CHF 10 million ($12.3 million) ransom demand from the Everest ransomware group, and by all accounts got away with it relatively intact.

The breach didn't touch Stadler's own systems. Instead, attackers got in through a data exchange platform the company shared with an unnamed supplier, using stolen credentials to access technical files. No personal data was taken, no production lines were disrupted, and the company's rolling stock kept rolling.

By the standards of ransomware incidents, that's a pretty clean outcome.

What's genuinely strange here isn't that Stadler refused to pay. It's that the company hasn't shown up on Everest's data leak site. That's not how this normally plays out.

The standard ransomware shakedown goes like this: steal data, tell the victim, demand money, threaten to publish. If the deadline passes without payment, the victim gets posted publicly. Then comes a second countdown, a final chance to pay before the files go live. Victims who pay get scrubbed. Victims who don't get their data dumped.

Stadler refused, and still hasn't appeared. That combination is unusual enough to raise an eyebrow.

Everest has been running since around December 2020 and has claimed hits on some fairly recognisable names over the years, including Under Armour, AT&T, Mailchimp, and Collins Aerospace. Whether they're holding back Stadler's data for strategic reasons or simply have less than they're claiming is anyone's guess.

For now, Stadler appears to have called the bluff. Whether Everest proves them wrong remains to be seen.

READ NEXT
Anubis Ransomware Gang Claims Fairlife Hit, Gives Coca-Cola One Week to PayArmenia Locks Up Russian Tourist Named Aleksandr Ermakov. Problem: There Are Two of Them.Play Ransomware Claims MyPillow Scalp — Lindell Says It's a Political Stitch-Up