Breaches · 53 days ago
The break is in the trust path, not Stadler’s own perimeter. A ransomware crew that can reach a shared supplier exchange can pull OEM data and pressure the company through partner access, which standard restore-and-recover playbooks do not fully cover.
Stadler Rail says Everest demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. Stadler refused to pay and says it is investigating possible supplier-linked data exfiltration.
For manufacturers and transportation operators, the risk sits in shared portals and integrations that connect suppliers to internal operations. Those links can carry the blast radius beyond one victim and into downstream confidentiality failures across the supply chain.
3 sources covering this story
Everest is demanding a $12.3 million ransom from rail manufacturer Stadler after breaching a supplier data exchange platform.
The Record from Recorded Future
Swiss train maker Stadler refuses Everest $12 million ransomware demand
Stadler Rail said it will not make a $12.3 million ransom payment after cybercriminals stole technical data from a supplier's file-sharing platform.
Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers.
Part of the PlainSec briefing for 2026-07-23