Stadler Rail Ransomware Attack: Swiss Train Giant Refused $12.3M

Stadler Rail rejected a $12.3M ransom after the Everest gang breached a supplier platform. Explore the attack, the fallout, and rising rail ransomware risks.

Stop Supplier Credentials From Becoming Enterprise Extortion
  • July 24, 2026

Refusing The Ransom: What Stadler Decided

Stadler Rail, the Swiss train manufacturer, refused a $12.3 million ransom demand after a July 2026 ransomware attack. The company stated plainly that it will not pay extortionists under any circumstances. Instead, it filed a criminal complaint with the Thurgau cantonal police.

Notably, the demand arrived as an extortion letter of 10 million Swiss francs. The Everest ransomware gang was named as the culprit, although the group had not publicly claimed the breach at disclosure.

Inside The Breach: How Attackers Got In

The attackers did not breach the network of Stadler directly. Instead, they accessed networks using compromised credentials linked to a data exchange platform of the supplier.

There were some reassuring aspects raised by Stadler:

  • The company’s internal IT infrastructure was not affected.
  • Manufacturing activities around the world were uninterrupted.
  • There were no personal details stolen.
  • The trains that run around the globe are not endangered.

Thus, the entire story looks like third-party data breaches. Nevertheless, the case proves once again that the weak spot of the supplier can become an attack vector for everyone.

Stadler Rail Refuses The Ransom

Ransom Demanded
$12.3M / CHF 10M
Threat Actor
Everest (Alleged)
Entry Point
Supplier Credentials
Sector
Rail & Manufacturing
The Refusal
  • Stadler refused the $12.3M / CHF 10M demand outright and filed a criminal complaint with Thurgau cantonal police.
  • Attackers entered via compromised credentials on a supplier data-exchange platform, not a direct breach.
  • Internal IT, global manufacturing, and personal data were unaffected; trains in service are not at risk.
Meet Everest
  • Surfaced in 2020 as a Russian-speaking crew; dropped encryption for pure data-theft extortion and now brokers network access too.
  • Claimed BMW, Collins Aerospace (Sept 2025 airport chaos), and Sweden’s grid operator (~280GB).
  • Original leak site defaced in April 2025; runs a new domain where Stadler isn’t listed yet.
Not Stadler’s First Rodeo
  • May 2020: attackers linked to Nefilim demanded ~$6M in Bitcoin. Stadler refused then too.
  • In response, internal documents leaked: bank contracts, a Thurgau tax agreement, and Altenrhein project files.
  • Two incidents, six years apart, the same hard-line answer: no payment.
Rail & Manufacturing Under Siege
Metric 2025
Manufacturing Attacks +56% (937 → 1,466)
Avg. Ransom Demand $523K → ~$1.2M
Transportation Attacks +34% year over year
Supply Chain Attacks 297 in 2025 (+93%)
Ransom Payment Rate Record low 23% (19% for data-theft-only)

Meet Everest: A Gang That Stopped Encrypting

Everest first surfaced in 2020 as a Russian-speaking ransomware crew. Since then, it dropped file encryption and pivoted to pure data-theft extortion. Today it steals files and threatens to publish them unless victims pay.

Moreover, the group often works as an initial access broker, selling network footholds to other criminals. Its recent claimed victims form a striking list:

  • BMW
  • Collins Aerospace, linked to September 2025 airport chaos across Europe
  • Svenska kraftnät, Sweden’s grid operator, which Everest claimed on October 25, 2025 to have hit for roughly 280 GB via an external file-transfer solution

Interestingly, Everest’s original leak site was defaced in April 2025 with a mocking message from Prague. The gang now runs a new domain, and Stadler does not yet appear on it.

History Repeats: Stadler’s 2020 Attack

This is not Stadler’s first brush with extortion. Back in May 2020, hackers infiltrated its network, planted malware, and demanded roughly $6 million in Bitcoin.

Then, as now, the company refused to negotiate. In response, the attackers leaked internal documents, including bank contracts, a Thurgau tax agreement, and material tied to an Altenrhein construction project. Analysts attributed that attack to the Nefilim ransomware group, though Stadler never officially confirmed it.

Therefore, Stadler’s latest refusal fits a consistent, hard-line pattern.

The Bigger Picture: Rail And Manufacturing Under Siege

Stadler sits at a dangerous intersection, rail transport and industrial manufacturing. Both sectors now attract heavy criminal attention.

Consider the numbers from last year:

  • Manufacturing became the single most-targeted sector.
  • Attacks on manufacturers climbed 56%, from 937 in 2024 to 1,466 in 2025.
  • Average manufacturing ransom demands more than doubled, from $523,000 in 2024 to nearly $1.2 million in 2025.
  • Transportation-sector attacks rose 34% year over year.

Rail operators have felt the pain directly. For instance, a December 2024 ransomware attack on Pittsburgh Regional Transit disrupted rail services and exposed data. Earlier, a 2021 attack knocked Northern Trains’ ticket machines offline for about a week.

Supply Chains: The Soft Underbelly

The statistics are sobering. Last year reports found third-party involvement in breaches doubled from 15% to 30% in a single year. 297 supply chain attacks in 2025, up 93% from 154 in 2024.

Because rail supply chains blend sensitive technical data, critical infrastructure contracts, and sprawling IT environments, they make especially tempting targets.

Saying No Pays Off: The Refusal Trend

Record-low numbers were observed in 2025. In the third quarter report of 2025, it is stated that there were record low payment rates, at only 23%, and for data exfiltration attacks without any encryption the number was 19%. On the other hand, many countries have started discouraging ransom payment especially in cases involving critical infrastructures.

It is quite simple. Payment will not guarantee deletion, will fund further crimes, and will invite more attacks.

Conclusion: When Supplier Credentials Become Enterprise Extortion

The Stadler Rail incident shows that attackers do not need to breach the target organization directly to create enterprise-level pressure.

Compromised credentials for a supplier data exchange platform were enough to expose technical information and trigger a ransom demand of 10 million Swiss francs. Stadler’s internal IT systems remained intact. Global production continued normally. Rail vehicles were not affected.

The breach happened outside Stadler.
The extortion still reached Stadler.

Why This Threat Matters

Modern rail and manufacturing organizations depend on suppliers, engineering partners, contractors, and shared platforms to exchange sensitive operational information.

That trust creates reach.

  • Supplier accounts can provide access without breaching the primary organization
  • Shared platforms can hold technical data from multiple companies
  • Stolen credentials can make malicious access appear legitimate
  • External identities may receive more access than their business purpose requires
  • Data theft can create extortion pressure without encryption
  • One compromised partner can expose an entire commercial relationship

Everest demonstrates how ransomware economics are moving beyond file encryption. Attackers can steal data, threaten disclosure, and demand payment without disrupting the victim’s production environment.

Where Xcitium Changes the Outcome

This type of attack must be addressed at two points, before compromised identities become trusted access and before malicious execution steals the credentials that enable it.

Xcitium ITDR strengthens the identity layer by identifying abnormal use of privileged accounts, third-party identities, cloud credentials, and access patterns that no longer match expected behavior.

A valid password should not make suspicious access automatically trustworthy.
A supplier identity should not receive unrestricted reach.
Authentication should not end the security decision.

Xcitium Advanced EDR, powered by Xcitium’s patented Zero-Dwell platform, applies Execution Governance when unknown tools, scripts, credential stealers, or exfiltration utilities attempt to run on managed systems.

Unknown code does not receive unrestricted execution rights.
Code can run without being able to cause damage.
Credential harvesting and follow-on activity are governed before trust exists.

Detection asks, “Were valid credentials used?”
Identity security asks, “Does this access still match the identity?”
Execution Governance asks, “Could the code behind the compromise cause damage at all?”

Together, these controls reduce the chance that one stolen supplier credential becomes enterprise extortion.

Refuse the Ransom. Remove the Leverage.

Stadler’s refusal sends an important message. Paying does not guarantee deletion, prevent resale, or stop future attacks.

But refusing payment happens after the data has already left.

The stronger objective is to prevent attackers from gaining leverage in the first place.

Review every supplier identity.
Restrict access to the minimum required.
Monitor shared platforms for abnormal behavior.
Revoke exposed credentials immediately.
Govern unknown execution before credentials can be harvested.

Like what you see? Share with a friend.

Move Away From Detection With Patented Threat Prevention Built For Today's Challenges.

No one can stop zero-day malware from entering your network, but Xcitium can prevent if from causing any damage. Zero infection. Zero damage.

Book a Demo