Stadler Rail Rejects $12.3M Ransom Demand from Everest Ransomware Gang

Stadler Rail Rejects $12.3M Ransom Demand from Everest Ransomware Gang

First seen 23 Jul 2026, 01:23 UTC BleepingcomputerFeeds.Feedburner 88% similarity 48.9

Article Content

Browse articles
ThreatCluster

Swiss rail manufacturer Stadler Rail confirmed a ransomware attack by the Everest gang, which demanded $12.3 million after breaching a data exchange platform with a supplier. The incident occurred in mid-July 2026, resulting in the theft of non-security-relevant technical information. Stadler Rail stated that its own IT systems and production operations remain unaffected and continue as normal. The company has refused to pay the ransom and has filed a criminal complaint with local authorities. Everest, known for shifting from encryption to data theft since 2020, has not publicly claimed responsibility for this attack. Stadler previously experienced a cybersecurity incident in 2020, which involved a similar breach. This event highlights the ongoing threat of ransomware targeting large corporations.

Key Points: • Stadler Rail faced a ransomware attack from the Everest gang demanding $12.3 million. • The breach involved non-security-relevant technical information from a supplier. • Stadler Rail's IT systems and production operations were not impacted by the attack.

ThreatCluster AI

Timeline

2026-07-15
Ransomware attack detected
Stadler Rail confirmed a breach involving the Everest ransomware gang, impacting a supplier's data exchange platform.
BleepingComputer
2026-07-22
Stadler Rail refuses ransom
Stadler Rail publicly announced it would not pay the $12.3 million ransom and filed a criminal complaint.
BleepingComputer
2026-07-22
Details of the attack disclosed
Stadler Rail confirmed that the attack involved theft of non-security-relevant technical information.
Feeds.Feedburner

Community

Browse all →