
Swiss train manufacturer Stadler Rail confirmed it was targeted in a cyberattack in mid-July after the Everest ransomware group demanded roughly 10 million Swiss francs, or about $12.3 million, not to release stolen technical data.
Stadler said the attackers gained access to a data exchange platform it shared with one of its suppliers using compromised login credentials, allowing them to reach technical information belonging to that supplier rather than Stadler’s own systems. The company said its internal IT infrastructure "were not compromised and remain intact," and that no data had been lost from its own networks.
The manufacturer said the material taken was not related to safety and that no personal data of consequence was exposed. Stadler said its rail vehicles in service worldwide were not affected by the breach and that production was continuing without interruption at its facilities.
Stadler said it received an extortion letter from the group and rejected the demand outright. "Stadler will not pay any ransom under any circumstances and is therefore not susceptible to extortion," the company said. It has filed a criminal complaint with police in the canton of Thurgau.
Stadler builds locomotives, trams, metro trains, passenger rail cars and signaling systems, and supplies rail operators around the world. The company employs 18,000 people across eight production facilities and six engineering sites, and reports annual revenue exceeding $4.9 billion.
Everest is described as a financially motivated, Russian-speaking hacking group that has operated since around 2020. Rather than encrypting victims’ systems, the group typically steals data and threatens to publish or sell it if payment is not made. Its previous claimed targets include automaker BMW, aerospace systems supplier Collins Aerospace and Swedish national grid operator Svenska kraftnät. The group has also acted as an initial access broker, selling entry into breached networks to other hackers, and has at times used data stolen by other actors to run its own extortion schemes.
The gang’s original dark web leak site was defaced in April 2025 with a message reading, "Don’t do crime CRIME IS BAD xoxo from Prague," and the group has since begun operating from a new domain. As of the most recent information available, Stadler Rail had not been listed on Everest’s extortion site, and the group had not publicly claimed the attack.
This is not the first cybersecurity incident to hit the company. In 2020, an unidentified hacking group infiltrated Stadler’s IT systems, deployed malware across parts of its infrastructure and extracted data from affected devices. The episode carried the hallmarks of a ransomware attack, though Stadler stopped short of confirming that characterization at the time.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543