Swiss rail manufacturer Stadler Rail rejected a ransom demand from the Everest gang following a breach of a supplier data exchange platform. The attackers demanded approximately $12.3 million for stolen data.
Stadler Rail, a major Swiss manufacturer of rail vehicles, confirmed it was targeted by the Everest ransomware group after a cyberattack compromised a shared data platform used with one of its suppliers.
The attackers demanded $12.3 million in exchange for not releasing the stolen information. Stadler declined to pay, stating it would not negotiate with the threat actors.
The breach affected a data exchange platform—a common IT infrastructure used by companies to share files with business partners. The shared nature of such platforms means the attack potentially exposed data from multiple organizations connected to Stadler's supplier network.
Everest is a known ransomware-as-a-service (RaaS) operation that has targeted organizations across multiple sectors. The group typically exfiltrates data before deploying encryption, then demands payment under threat of public data release.
Stadler Rail's refusal to pay aligns with guidance from law enforcement and cybersecurity authorities, who discourage ransom payments as they fund criminal operations and encourage further attacks. The company stated it was working with cybersecurity experts and relevant authorities to investigate the incident.
No details were provided regarding the extent of data accessed or whether any customer or employee information was compromised. The company did not disclose how long the breach went undetected or when it was discovered.
Railway and transportation infrastructure remains a critical sector facing increased cybersecurity threats. Attacks on manufacturers in this space can have significant operational and supply chain implications across Europe.
Stadler Rail produces rail vehicles for operators across Switzerland and internationally. The company has not announced service disruptions related to the incident, suggesting operational systems were not affected by the breach.
A child sexual abuse survivor has filed a lawsuit against Elon Musk's AI company, alleging that Grok generated new illegal pornographic images using pictures of her abuse. Musk denied awareness of the chatbot producing such content.
A UNICEF survey of 21,000 internet-using children across 21 countries found nearly one in five experienced tech-facilitated sexual exploitation and abuse. The report reveals a critical gap in reporting, with less than 1% of cases reaching authorities.
A massive data breach at an unspecified car rental company exposed customer driver's licenses and personal information within hours of rental. The FBI is investigating the incident as data stolen from customers appears for sale online.