Stadler Rail Refuses 10M Franc Ransom After Everest Attack

Step by step
How the attack unfolded
Click a phase for details – or let the animation play through.
PHASE 1/4 · Initial Access

The Everest group entered a data-exchange platform shared with a supplier using stolen but valid credentials.

T1078 – Valid Accounts T1199 – Trusted Relationship
  • No software vulnerability and no CVE – pure credential abuse (T1078)
  • Entry point was a third-party platform outside Stadler's core systems
  • Stadler's own IT, ERP and production systems remained untouched
  • Everest has actively recruited insiders for credentials since October 2023, per Halcyon
PHASE 2/4 · Collection

Through the compromised platform the attackers gathered technical information belonging to the supplier.

T1213 – Data from Information Repositories
  • Technical documents of the unnamed supplier were seized
  • No relevant personal data affected, according to Stadler
  • Safety-relevant vehicle data was not affected
PHASE 3/4 · Exfiltration

The data was exfiltrated out of the environment via the cloud-based exchange platform.

T1567 – Exfiltration Over Web Service
  • Since around 2024 Everest skips encryption and relies on pure data-theft extortion
  • Over 116 victims in the previous twelve months (as of July 2026)
  • Per Halcyon, Everest specifically breaches supplier-managed file-transfer systems
PHASE 4/4 · Impact

Everest demanded CHF 10 million in ransom – Stadler refused to pay and filed a criminal complaint.

T1657 – Financial Theft
  • Ransom demand of CHF 10 million (approx. USD 12.3 million)
  • Stadler did not pay and filed a criminal complaint with the Thurgau cantonal police
  • As of late July 2026, no publication on the Everest leak site
  • Suspicion: the stolen data was not valuable enough for credible extortion
Short & clear answers
Frequently asked questions about this incident
Am I affected by this attack?
This specific incident hit the shared data-exchange platform of Stadler Rail and a supplier, not other companies directly. However, you are exposed to the same attack path if you use file-sharing or data-exchange platforms (e.g. SharePoint, Dropbox Business, customer portals) jointly with suppliers or customers. Check haveibeenpwned.com to see whether your credentials appear in known data breaches.
What do I need to do right now?
Immediately enable multi-factor authentication (MFA) for all external platforms, VPN access, email and cloud services – it is the single most effective measure against stolen credentials. Then change all passwords for external and supplier-shared platforms (at least 16 characters, unique, managed via a password manager). Also remove access for former employees and suppliers you no longer work with without delay.
Is there a patch or update to fix this vulnerability?
No. The attack did not exploit a software flaw but used stolen yet valid credentials (MITRE ATT&CK T1078 'Valid Accounts'). There is therefore no CVE number and no patch – the only protection comes from better processes, MFA and strict access management.
Why is this relevant for my small business if I'm not a large corporation?
The point of entry was not a highly specialised industrial system but an ordinary data-exchange platform used by almost every company. Such shared platforms are often less well protected than core systems because multiple parties have access. Supply-chain attacks rose 93% in 2025 to 297 cases, and third-party involvement in data breaches doubled within a year to 30%.
Should I pay the ransom in a ransomware extortion attempt?
Stadler Rail refused to pay in both 2026 (CHF 10 million demand) and 2020 (approx. USD 6 million) and filed criminal complaints each time. In the current case the attackers did not even publish the data – likely because it wasn't valuable enough for a credible extortion. Data minimisation on shared platforms is therefore a real protective factor, and filing a police report while handling the incident openly are proven approaches.
More security news
You might also be interested in
Critical Elementor Pro Flaw: Attackers Can Fully Take Over WordPress Sites
A file upload bug in Elementor Pro up to 4.2.1 allows RCE without login. Version 4.2.2 fixes the flaw – update now!
Pods Plugin: Critical Flaw Enables Admin Takeover, No Login
A critical flaw in the WordPress plugin Pods lets attackers overwrite admin passwords without login. Over 100,000 sites are affected.
miniOrange SAML SSO: Critical Bypass Turns Attackers Into Admins
Two critical auth bypasses in the miniOrange SAML SSO plugin allow forged SAML assertions—up to full WordPress admin access.