logo

Swiss train maker Stadler refuses Everest $12 million ransomware demand

ID: 422eb5f5-9666-5ef1-9dfd-7295ff026a5d

STIX ID: report--422eb5f5-9666-5ef1-9dfd-7295ff026a5d

Feed Name: The Record from Recorded Future News

Threat Score
55/100

Date Published: 2026-07-22

Date Updated: 2026-07-23

...
...

Swiss train manufacturer Stadler Rail reported that credentials to a supplier's file-sharing platform were compromised in mid-July, resulting in theft of supplier technical documents and an extortion demand of 10 million CHF by the Everest ransomware group; Stadler said its own systems and production were unaffected, has filed a criminal complaint, and refused to pay. The report notes this is a repeat extortion attempt (a 2020 incident is referenced) and situates Everest as an active Russian-speaking ransomware/extortion group that targets critical infrastructure and third-party vendors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.