logo

Swiss Rail Giant Stadler Rejects $12.3M Ransom Demand After Cyberattack

ID: 9ede6fc9-64b7-5c68-9306-22daebbd7ed9

STIX ID: report--9ede6fc9-64b7-5c68-9306-22daebbd7ed9

Feed Name: CosmicBytez Labs

Threat Score
70/100

Date Published: 2026-07-22

Date Updated: 2026-07-23

...
...

In mid‑July 2026 the Everest ransomware group accessed a third‑party supplier file‑sharing platform used by Stadler Rail, downloaded internal business and project documents, and demanded CHF 10 million in cryptocurrency; Stadler reported no compromise of its core IT or production systems, declined to pay, and filed a police report. The report profiles Everest's double‑extortion model and insider recruitment tactics, frames the incident as a supply‑chain/third‑party risk to the rail sector, and lists immediate mitigations such as enforcing MFA, auditing shared platforms, and applying least privilege.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.