Ransomware

Stadler Rail Refuses $12.3 Million Ransom Demand After Supplier Platform Breach

Stadler Rail, the Swiss rolling stock manufacturer, has refused to pay a $12.3 million ransom demand from the Everest ransomware group following a breach on a shared data exchange platform the company uses with one of its suppliers. Stadler confirmed no personal data was taken and that its own production systems were not affected. The company has filed a criminal complaint with the Thurgau Cantonal Police.

The position is unambiguous. “Under no circumstances will Stadler pay a ransom,” the company stated publicly. That refusal carries a predictable consequence, Everest has threatened to publish stolen technical documents if no payment is received.

The Breach Was on the Supplier Side, Not Inside Stadler

The entry point was a shared platform used for data exchange between Stadler and one of its suppliers not Stadler’s internal network. That distinction matters operationally, Stadler’s production line kept running and the company says its core systems were not touched. What Everest claims to hold is technical documentation extracted from that shared environment.

The attack illustrates a pattern that is becoming routine in industrial ransomware, attackers who cannot get through the primary target’s perimeter look for a supplier with shared access and lighter security controls. Everest has used this approach before. The group has been active since at least 2020 and has targeted critical infrastructure operators and industrial manufacturers across multiple continents according to BleepingComputer’s tracking of the group’s activity.

What Everest Will Likely Do Next

Ransomware groups that fail to collect payment almost always follow through on publication. Everest operates a data leak site and has published stolen files from previous victims who refused to pay. Stadler’s leadership will have assessed that risk before issuing a public refusal which suggests the company either believes the stolen documents carry manageable exposure or has concluded that paying would set a worse precedent.

The honest answer is that Everest’s threats of publication should not be treated as a negotiating tactic. They are standard operating procedure. Any organisation watching this incident and assuming that a firm refusal ends the matter is misreading how these groups operate.

Supply Chain Access Is the Exposed Surface

The Nordic angle here is not speculative. Stadler operates maintenance and service contracts across the Nordic rail network. Its trains run in Sweden under Transdev and SJ contracts and the company has active relationships with operators in Norway and Finland. Any shared digital platform in that supplier ecosystem carries the same structural exposure that Everest exploited here.

The question for Nordic rail operators and transport authorities is not whether they have been breached. It is whether they have mapped the shared platforms, credentials and data exchange agreements they hold with all their rolling stock and maintenance suppliers, and whether those environments are subject to the same security standards as their internal systems. Most are not.

NIS2 which entered Swedish law as Cybersäkerhetslagen on 15 January 2026 places explicit supply chain security obligations on essential entities. Transport operators classified as essential under that law are required to assess the security practices of their suppliers and document those assessments. A shared data exchange platform with a manufacturer is exactly the kind of third-party dependency Article 21 is designed to capture.

Shared Platforms Need Contractual Security Floors

Stadler’s situation is a useful illustration of what supply chain security obligations look like in practice rather than in policy documents. Shared platforms require agreed minimum security standards between all parties that use them not just the platform operator. Access should be scoped to what each party actually needs. Audit logs from those environments should flow to someone who reviews them.

Incident response plans need to account for breaches that originate outside your own perimeter. If your plan assumes the first alert will come from your own detection tooling, it will not catch an attacker who entered through a supplier and is sitting on a shared platform your monitoring does not cover.

Stadler has filed its criminal complaint and refused the ransom. Whether Everest publishes will become clear in the coming days. The criminal investigation sits with the Thurgau Cantonal Police.

References

  1. Swiss Train Maker Stadler Refuses Everest $12 million Ransomware Demand
  2. Swiss Rail Giant Stadler Rejects $12.3M Ransom Demand After Cyberattack
  3. Swiss Rail Manufacturer Stadler Refuses to Pay $12.3 Million Ransom
  4. Stadler Rail Refuses to Pay $12.3 Million Ransom After Ransomware Attack
  5. NIS2 Directive Full Text, Article 21

This post is also available in: Svenska

Per Häggdahl

Per Häggdahl is Head of Business Unit and CISO at eBuilder Security, with more than 20 years securing systems for banks, central banks, stock exchanges and central securities depositories, now leading the team that brings that same enterprise-grade protection to organisations of every size.