Swiss train manufacturer Stadler Rail has confirmed it will not pay a $12.3 million ransom demand from the Everest extortion group following a breach of a data exchange platform shared with one of its suppliers. The company says its own systems and production sites were not affected.
According to Stadler’s statement, the incident occurred in mid-July when attackers compromised credentials for a third-party file-sharing platform, stealing technical documents belonging to a supplier. The company said no personal data of relevance was taken and that trains operating worldwide are not impacted. Global production, spanning eight facilities and six engineering sites, continues as normal.
Everest sent Stadler an extortion letter demanding 10 million Swiss francs, roughly $12.3 million. Stadler said it has filed a criminal complaint with Thurgau cantonal police and rejected the demand outright. “Stadler will not pay any ransom under any circumstances and is therefore not susceptible to extortion,” the company said.
As of publication, Everest had not listed Stadler on its dark web leak site, and it remains unclear whether the group has begun releasing any stolen supplier data.
Background on Everest
Everest is a Russian-speaking threat group active since at least 2020. It originally operated as a ransomware operation but has shifted toward pure data theft and extortion, sometimes acting as an initial access broker or acquiring data stolen by other actors to run its own campaigns. The group’s original leak site was defaced in April 2025 with a message mocking its operations, and it has since moved to a new domain.
Everest has previously claimed attacks involving Sweden’s grid operator Svenska kraftnat and a contractor tied to Nissan, though neither incident was confirmed to have caused operational disruption.
This marks the second known extortion attempt against Stadler. In 2020, an unknown group infiltrated the company’s own IT systems and demanded roughly $6 million in bitcoin. Stadler refused to pay then as well, and the attackers subsequently leaked samples of financial and administrative documents. The company says it stood by that decision despite the leak, and is taking the same approach this time.
