Swiss Train Manufacturer Stadler Rail Rejects $12.3 Million Ransom Demand
Stadler Rail refuses to pay Everest ransomware after data breach; denies impact on operations.

Key points
- Stadler Rail faced a ransom demand of $12.3 million from Everest ransomware in July 2023.
- The hackers accessed a data exchange platform shared with a supplier but did not disrupt Stadler's operations.
- Stadler Rail employs 18,000 people and has an annual revenue of $4.9 billion.
- The Everest group now focuses on data theft rather than encrypting victims' files.
- Stadler reported the incident to the Thurgau cantonal police and filed a criminal complaint.
Swiss train manufacturer Stadler Rail refused to pay a $12.3 million ransom demanded by the Everest ransomware group. The hackers broke into a data exchange platform shared with one of Stadler’s suppliers, but the company stated its operations were not affected.
Stadler Rail, a major player in the rail manufacturing industry, builds a wide range of trains and signaling systems. It employs 18,000 people and generates over $4.9 billion in annual revenue. Despite the breach, its IT systems and production continued as normal, according to the company's disclosure.
Everest ransomware, known for stealing data rather than locking up systems, demanded 10 million Swiss francs (about $12.3 million). Stadler, however, made it clear they would not comply, stating, “Stadler will not pay any ransom under any circumstances.” Instead, the company filed a criminal complaint with the local police.
This incident occurred in mid-July 2023, but Stadler assured that no critical technical or personal data was compromised. The stolen data was described as non-security-relevant technical information from a supplier.
How did the hackers get in?
The Everest group gained access through a shared data platform between Stadler and a supplier. However, the attack did not affect Stadler’s global operations or production. The company confirmed that its rail vehicles and systems worldwide were not impacted by the hack.
Everest ransomware first appeared in 2020. Initially, they encrypted files on victims' networks, but have since shifted to stealing data and demanding payment to avoid its release. They have also acted as an initial access broker, selling access to other hackers.
Stadler Rail has faced cyber incidents before. In 2020, an unknown group infected its systems with malware and stole data. This incident appeared to be a ransomware attack, although Stadler did not confirm this at the time.
Stadler Rail’s recent experience with Everest highlights the ongoing threat of ransomware groups evolving their tactics. While the company has not appeared on Everest's current extortion site, the potential for data leaks remains a concern.



