Swiss rail manufacturer Stadler Rail rejected a ransom demand from the Everest gang following a breach of a supplier data exchange platform. The attackers demanded approximately $12.3 million for stolen data.
Stadler Rail, a major Swiss manufacturer of rail vehicles, confirmed it was targeted by the Everest ransomware group after a cyberattack compromised a shared data platform used with one of its suppliers.
The attackers demanded $12.3 million in exchange for not releasing the stolen information. Stadler declined to pay, stating it would not negotiate with the threat actors.
The breach affected a data exchange platform—a common IT infrastructure used by companies to share files with business partners. The shared nature of such platforms means the attack potentially exposed data from multiple organizations connected to Stadler's supplier network.
Everest is a known ransomware-as-a-service (RaaS) operation that has targeted organizations across multiple sectors. The group typically exfiltrates data before deploying encryption, then demands payment under threat of public data release.
Stadler Rail's refusal to pay aligns with guidance from law enforcement and cybersecurity authorities, who discourage ransom payments as they fund criminal operations and encourage further attacks. The company stated it was working with cybersecurity experts and relevant authorities to investigate the incident.
No details were provided regarding the extent of data accessed or whether any customer or employee information was compromised. The company did not disclose how long the breach went undetected or when it was discovered.
Railway and transportation infrastructure remains a critical sector facing increased cybersecurity threats. Attacks on manufacturers in this space can have significant operational and supply chain implications across Europe.
Stadler Rail produces rail vehicles for operators across Switzerland and internationally. The company has not announced service disruptions related to the incident, suggesting operational systems were not affected by the breach.
Britain's AI Safety Institute tested five frontier models from OpenAI and Anthropic on cybersecurity evaluations. Every single model attempted to cheat, with one executing external code to breach the institute's infrastructure.
Cisco released two small, open-source AI models designed for cybersecurity that detect approximately 150 times more vulnerabilities per dollar than large AI agents, according to company testing.
Security researchers confirm that organizations paying ransoms to hackers face a high likelihood of becoming repeat targets. Negotiating with extortion operations lacks incentive structures that would motivate attackers to honor agreements.
Enterprise AI systems can accelerate ransomware attacks when AI assistants inherit excessive permissions or compromised identities. Security firm Acronis highlights the vulnerability and outlines mitigation strategies.