[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f6f_Wij9wqLBNQbK-t74YY49AaDicD6Uu1iF3-dLZYM4":3},{"article":4,"iocs":42},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"55e5f051-82e3-451c-aeb6-e9fd2e22f2de","Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack","swiss-rail-giant-stadler-rejects-12-3m-ransom-demand-after-cyberattack-8b2bec","Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. [...]","Swiss rail manufacturer Stadler Rail has refused to pay a ransom of approximately $12.3 million demanded by the Everest ransomware gang. The attackers breached a data exchange platform shared with a supplier and allegedly stole technical information, though Stadler states no critical systems or personal data were compromised. The company has filed a criminal complaint and confirmed that its global operations remain unaffected.","Stadler Rail rejects $12.3M ransom demand from Everest ransomware gang after data breach.","Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack By Bill Toulas July 22, 2026 12:59 PM 1 Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. The threat actor has not publicly claimed the attack, but the Swiss company says that it received an extortion letter from Everest ransomware asking for a ransom of 10 million Swiss francs. The company responded by saying that it will not pay the threat actor and filed a criminal complaint with the Thurgau cantonal police. \"Stadler will not pay any ransom under any circumstances and is therefore not susceptible to extortion.\" Stadler Rail is a large, multinational Swiss train manufacturer that builds locomotives, trams, metro trains, passenger trains, and railway signaling systems. The company supplies rail operators worldwide, employs 18,000 people working in 8 production facilities and 6 engineering sites, and has an annual revenue of over $4.9 billion. Stadler said that the incident occurred in mid-July and neither its IT systems nor its production operations were impacted, and continue as normal globally. According to the company's disclosure, the hackers stole from a supplier only technical information that is not security relevant. \"No relevant personal data was stolen. Stadler's rail vehicles operating worldwide are not affected by the data theft. Stadler's global production continues as normal.\" Everest is a threat group that emerged in 2020 as a ransomware operation but abandoned the network encryption tactic in favor of data theft. The gang now threatens victims with leaking the stolen data unless a ransom is paid. In the past, Everest sold its access to the networks it breached to other threat actors, acting as an initial access broker. Sometimes, the hackers acquired data stolen by other threat actors to conduct their own extortion campaigns. Currently, the Everest ransomware gang is operating a new domain, after its original dark web leak site was defaced in April 2025 with the message: \"Don't do crime CRIME IS BAD xoxo from Prague.\" Stadler Rail is not yet listed on the gang's extortion site. In 2020, Stadler suffered a cybersecurity incident where an unknown hacking group infiltrated its IT systems, infected parts of its infrastructure with malware, and stole data from compromised devices. The case appeared to be a ransomware attack, though Stadler did not confirm it at the time. Test every layer before attackers do Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Get the whitepaper Related Articles: New Helix vishing group emerges in SharePoint data theft attacksMount Royal University confirms breach as hackers claim attackEntra passkey enrollment vishing targets Microsoft 365 usersNAIC says public data stolen in ShinyHunters' PeopleSoft breachSilent Ransom Group targets law firms with fake IT support calls","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fswiss-rail-giant-stadler-rejects-123m-ransom-demand-after-cyberattack\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2026\u002F07\u002F22\u002Fstadler.jpg","2026-07-22T16:59:17+00:00","2026-07-22T18:00:04.893123+00:00",7,[18,21],{"name":19,"type":20},"Stadler Rail","vendor",{"name":22,"type":23},"Everest ransomware gang","threat_actor","7d8b5ab8-ea0b-4ced-ae97-ec251b86993a",{"id":24,"icon":26,"name":27,"slug":28},null,"Ransomware","ransomware",[30,35,37],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":36},{"id":24,"icon":26,"name":27,"slug":28},{"category":38},{"id":39,"icon":26,"name":40,"slug":41},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[43],{"type":44,"value":45,"context":46},"malware","Everest ransomware","Ransomware group that demanded payment from Stadler Rail."]