:

STADLER RAIL REFUSES $12.3M RANSOM AFTER CYBERATTACK

AI DESK2 MIN READ
WED, JUL 22, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Swiss rail manufacturer Stadler Rail rejected a ransom demand from the Everest gang following a breach of a supplier data exchange platform. The attackers demanded approximately $12.3 million for stolen data.

Stadler Rail, a major Swiss manufacturer of rail vehicles, confirmed it was targeted by the Everest ransomware group after a cyberattack compromised a shared data platform used with one of its suppliers. The attackers demanded $12.3 million in exchange for not releasing the stolen information. Stadler declined to pay, stating it would not negotiate with the threat actors. The breach affected a data exchange platform—a common IT infrastructure used by companies to share files with business partners. The shared nature of such platforms means the attack potentially exposed data from multiple organizations connected to Stadler's supplier network. Everest is a known ransomware-as-a-service (RaaS) operation that has targeted organizations across multiple sectors. The group typically exfiltrates data before deploying encryption, then demands payment under threat of public data release. Stadler Rail's refusal to pay aligns with guidance from law enforcement and cybersecurity authorities, who discourage ransom payments as they fund criminal operations and encourage further attacks. The company stated it was working with cybersecurity experts and relevant authorities to investigate the incident. No details were provided regarding the extent of data accessed or whether any customer or employee information was compromised. The company did not disclose how long the breach went undetected or when it was discovered. Railway and transportation infrastructure remains a critical sector facing increased cybersecurity threats. Attacks on manufacturers in this space can have significant operational and supply chain implications across Europe. Stadler Rail produces rail vehicles for operators across Switzerland and internationally. The company has not announced service disruptions related to the incident, suggesting operational systems were not affected by the breach.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Plex has issued an urgent warning for users to update their desktop clients and media servers to address multiple security vulnerabilities.

JUST NOWSecurity Desk

A child sexual abuse survivor has filed a lawsuit against Elon Musk's AI company, alleging that Grok generated new illegal pornographic images using pictures of her abuse. Musk denied awareness of the chatbot producing such content.

1H AGOAI Desk

A UNICEF survey of 21,000 internet-using children across 21 countries found nearly one in five experienced tech-facilitated sexual exploitation and abuse. The report reveals a critical gap in reporting, with less than 1% of cases reaching authorities.

6H AGOSecurity Desk

A massive data breach at an unspecified car rental company exposed customer driver's licenses and personal information within hours of rental. The FBI is investigating the incident as data stolen from customers appears for sale online.

12H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.