# Stadler Rail Tells Everest Gang to Keep Its $12.3 Million Demand


When Swiss train manufacturer Stadler Rail received an extortion letter from the Everest ransomware gang last week, the company did something that most breach victims spend sleepless nights avoiding: it said no, publicly, without hesitation.


"Stadler will not pay any ransom under any circumstances and is therefore not susceptible to extortion," the company announced, filing a criminal complaint with Thurgau cantonal police the same day. It's the kind of posture every boardroom claims to have and most abandon the moment a clock starts ticking.


## The Breach They Actually Got


The attack hit a data exchange platform shared between Stadler and one of its suppliers — not Stadler's internal IT systems, not its production lines, not the operational technology controlling rail vehicles worldwide. The company was explicit on all three. What the Everest gang walked away with was "technical information that is not security relevant," and according to Stadler, no meaningful personal data.


That distinction matters. Stadler designs and builds locomotives, trams, metro systems, and passenger trains. It serves rail operators across the globe, employs 18,000 people across 14 facilities, and reports annual revenue over $4.9 billion. If production or OT systems had been compromised, the story would be categorically different. Instead, Everest appears to have popped a peripheral supplier portal and grabbed file transfers — valuable enough to extort someone over, but apparently not the crown jewels.


The ask was 10 million Swiss francs, roughly $12.3 million at current rates. Stadler declined.


## Who Is Everest, and Why Are They Just Stealing Now?


Everest emerged in 2020 as a fairly conventional ransomware operation — encrypt, demand payment, threaten to publish. Since then, the group has done something notable: it dropped the encryption entirely. The current model is pure data extortion. Steal files, threaten to leak, collect payment. No keys to hand over, no decryption headaches, no risk that a victim decides to restore from backup and walk away.


This shift tracks a broader industry-level trend. Encryption has always been the loud, disruptive piece of a ransomware attack — it forces victim organizations to act, but it also triggers incident response, law enforcement attention, and cyber insurance claims. Data theft extortion is quieter. The victim organization keeps running. The attacker's leverage is embarrassment, regulatory exposure, and whatever sensitivity lives in the files.


Everest has also operated as an initial access broker, selling footholds into breached networks to other threat actors. That model adds a secondary revenue stream but also creates supply chain risk for victims: even if the named attacker is paid or contained, the access may already have been sold.


One detail worth tracking: Everest's original dark web leak site was defaced in April 2025 — hacked and overwritten with "Don't do crime CRIME IS BAD xoxo from Prague." The gang now operates on a new domain, and Stadler is not yet listed on their extortion site. That could mean negotiations are ongoing, it could mean the data isn't as damaging as hoped, or it could mean Everest is still deciding how to play this.


## The Supplier Problem Nobody Wants to Talk About


The entry point here wasn't Stadler. It was a shared data exchange platform with one of its suppliers.


This is the third-party attack surface in its most literal form — a platform whose security posture presumably depends on the practices of at least two organizations, with access likely provisioned for operational convenience rather than zero-trust design. Large manufacturers lean on supplier portals for technical drawings, component specs, quality certifications, and logistics data. The collaborative nature of that relationship is exactly what attackers exploit.


Stadler's 2020 incident adds context. Six years ago, an unknown group infiltrated Stadler's IT systems, deployed malware, and stole data — an attack that carried the signatures of a ransomware campaign even though the company never confirmed it. Two incidents in six years for a company this size suggests either persistent adversary interest or systemic gaps in vendor security controls that haven't fully closed.


## What "No-Pay" Actually Accomplishes


Stadler's refusal is meaningful beyond the obvious optics. Every ransom paid funds the next campaign, validates the business model, and tells attackers that critical infrastructure operators are soft targets. A company with Stadler's revenue making the no-pay posture public — and filing with law enforcement immediately — sends a useful signal to the extortion ecosystem.


It also limits the utility of the stolen data as leverage. If the victim has already said publicly that no payment is coming, leaking the data no longer creates the same negotiating pressure. Everest still has the option to publish, but the extortion playbook loses a chapter.


---


## HackWire Analysis


The Stadler incident is less interesting as a ransomware story and more interesting as a mirror on how industrial supply chains have become the preferred attack surface for extortion groups.


Everest's decision to hit a supplier portal rather than Stadler's core environment was almost certainly deliberate. OT environments at major manufacturers are harder to breach and generate enormous law enforcement attention when disrupted. But supplier data exchanges? They're a softer target, often managed by smaller vendors with less security maturity, and they routinely hold technically sensitive documentation — schematics, tolerances, integration specs — that creates genuine embarrassment risk for the prime contractor even if "not security relevant" in the OT sense.


The pattern here maps closely to what we saw with MOVEit in 2023 and GoAnywhere in the same period: file transfer and data exchange platforms as the thin seam where enterprise supply chains are most vulnerable. Organizations hardened their direct attack surface and the attackers just pivoted to the connective tissue. Stadler isn't the only rail or transport manufacturer running these kinds of supplier portals. European transit infrastructure companies should be reading this and auditing every data exchange platform touching their supplier ecosystem — access controls, data minimization policies, and monitoring all need a hard look.


Everest's apparent disarray (defaced site, new infrastructure, no public Stadler listing yet) might tempt analysts to write them off. Don't. Reorganized ransomware operations often come back leaner and with better operational security. The Prague defacement was embarrassing, not fatal.


The bigger question is whether Stadler's no-pay posture holds if the data turns out to be more sensitive than currently disclosed. The company's statement is confident. The next few weeks will show whether Everest decides it's worth proving them wrong.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)