Stadler refuses to pay 10 million Swiss franc ransom after cyberattack

Image: Wikimedia Commons (CC0) — Syced

Stadler refuses to pay 10 million Swiss franc ransom after cyberattack

Swiss train maker Stadler says it will not pay a ransom after a hacker group stole technical data from a supplier platform.

Main source: Stadler refuses to pay SFr10m cyberattack ransom · By Rail Post Desk


Swiss rolling stock manufacturer Stadler Rail has confirmed it was targeted in a cyberattack in mid-July 2026. The Everest hacker group claimed to have stolen technical data and demanded 10 million Swiss francs not to exploit it.

According to railwaygazette.com, Stadler stated that under no circumstances would it pay a ransom. The attackers obtained compromised login credentials for a data-exchange platform used with one of Stadler’s suppliers, allowing them to access technical information belonging to that supplier.

Stadler said its own IT systems were not compromised and remain intact, and no data had been lost from its systems. The stolen information was not safety-related and no relevant personal data was taken, according to the manufacturer. Stadler added that its rail vehicles in operation worldwide were unaffected and that production was continuing normally.

The Everest hacker group claimed responsibility in a letter demanding the payment. Stadler said it was not susceptible to blackmail and has filed a criminal complaint with the Thurgau cantonal police.

Everest is a financially motivated, Russian-speaking hacker group that has been active since around 2020. It typically steals data and threatens to publish or sell it unless victims pay, rather than encrypting their systems. The group has targeted organisations across the aviation, telecommunications and energy sectors, with previous claimed victims including carmaker BMW, aerospace systems supplier Collins Aerospace and Sweden’s national power grid operator Svenska kraftnät.

The incident comes as the European Union cybersecurity agency ENISA warned that the railway sector’s growing strategic importance was outpacing its ability to manage cyber risks. Its May 2026 assessment placed rail in a cybersecurity risk zone, saying the sector had become more critical because of its role in military logistics and heightened exposure to cyber threat.

The findings point to weaknesses closely related to the Stadler breach. Only 35% of railway companies surveyed regularly assessed the effectiveness of their cybersecurity controls, while 50% did so on an ad hoc basis. Just 25% regularly tested business-continuity and disaster-recovery arrangements.

Only around three in five railway companies included operational technology such as signalling and train-control systems in their cyber-risk assessments, with ENISA warning that long-lived, highly integrated systems involving multiple suppliers were difficult to map, patch and secure.

Addressing the access management challenges in complex, multi-user or multi-company operational environments such as railways is key, ENISA said, adding that stronger control over third-party access was needed.