Cyber Incident Victim: Stadler
Date:
Jul 2026
Location:
Switzerland
Summary
Stadler Rail confirmed a cyberattack in which the Everest ransomware group demanded ten million Swiss francs, about twelve million dollars, not to release stolen technical data. The attackers entered through a compromised login on a data exchange platform shared with a supplier, obtaining that supplier’s technical information while the company’s own systems remained intact and no safety‑related or personal data was exposed. The company said its rail vehicles in service were unaffected and production continued without interruption, rejected the extortion demand outright, and filed a criminal complaint with local police.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
In mid‑July 2026 Stadler Rail confirmed that it had been targeted by the Everest ransomware group, which demanded roughly 10 million Swiss francs, or about $12.3 million, to refrain from publishing stolen technical data. The attackers gained entry to a data exchange platform that Stadler shared with one of its suppliers by using compromised login credentials, which allowed them to access technical information belonging to that supplier rather than Stadler’s own internal systems. Stadler stated that its internal IT infrastructure was not compromised and remained intact, and that no data had been lost from its networks. The company emphasized that the exfiltrated material was unrelated to safety and that no personal data of consequence had been exposed.

Stadler reported that its rail vehicles in service worldwide were unaffected by the breach and that production continued without interruption at its facilities. After receiving an extortion letter from Everest, Stadler publicly declared that it would not pay any ransom under any circumstances and therefore was not susceptible to extortion. The manufacturer filed a criminal complaint with police in the canton of Thurgau to pursue legal action against the perpetrators. Stadler employs approximately 18,000 people across eight production facilities and six engineering sites and reports annual revenue exceeding $4.9 billion, underscoring the scale of its operations.
Everest is described as a financially motivated, Russian‑speaking hacking group active since around 2020 that typically steals data and threatens to publish or sell it unless a ransom is paid, rather than encrypting victims’ systems. The group has previously claimed targets such as BMW, Collins Aerospace and Svenska kraftnät, and has also acted as an initial access broker selling network access to other criminals. Everest’s original dark web leak site was defaced in April 2025 with a message reading “Don’t do crime CRIME IS BAD xoxo from Prague,” after which the group moved to a new domain; as of the latest information, Stadler Rail had not appeared on Everest’s extortion site and the group had not publicly claimed the attack. This incident follows a 2020 cybersecurity event in which an unidentified hacking group infiltrated Stadler’s IT systems, deployed malware across parts of its infrastructure and extracted data, although Stadler did not formally characterize that episode as ransomware at the time.
