Swiss train maker refuses to pay hackers, citing minimal data impact
The Everest ransom gang demanded $12M+ for stolen data

Image by Cybernews.
- Stadler refused Everest’s $12 million ransom, saying stolen supplier data posed no security risk
- The breach involved compromised supplier credentials, but operations and production remained fully unaffected
- Unusually, Everest neither leaked Stadler’s data nor listed the company on its site
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
This happens rarely but Stadler Rail, a Swiss rail manufacturer, has publicly refused to pay a CHF 10 million ($12.3 million) ransom to the Everest ransomware gang that had earlier compromised one of its suppliers.
According to Stadler, “no relevant personal data was stolen,” and the breach itself was limited to “technical information from a supplier.”
Furthermore, the incident had no impact on Stadler’s global production lines and the functioning of its train and tram carriages, the company explained, also unusually naming the Everest gang directly in its statement.
“In an extortion letter, the cybercriminal Everest group claimed responsibility for the data theft. They demanded a ransom of 10 million Swiss francs. Stadler will not pay any ransom under any circumstances and is therefore not susceptible to extortion,” the manufacturer said.
Check if your data has been leaked
The press release ends with a pretty cold line: “The company has filed a criminal complaint with the Thurgau cantonal police. Thank you for your understanding.”
The Everest gang appears to have accessed the technical data through a “data exchange platform” the manufacturer used with the unnamed supplier. The hackers got it using compromised login credentials.
The case is unusual in another aspect as well. If a targeted organization fails to meet the deadline or simply refuses to pay the ransom, it typically appears on the ransomware gang’s data leak site.
The crooks then usually give the victim a few more days, sometimes also posting data samples to show they’re serious. If the victim pays up, their name disappears from the data leak site – and if the target doesn’t, their data is leaked.
Everest might have realized they hadn’t grabbed anything of true value when they breached the systems of Stadler’s supplier.
But Stadler hasn’t been named on Everest’s site. Moreover, the stolen data doesn’t appear to have been leaked – even when the company very publicly said it wouldn’t pay any money to the hackers.
That’s a very rare combination but Everest might have realized they hadn’t grabbed anything of true value when they breached the systems of Stadler’s supplier.
Everest is one of the most aggressive ransomware groups in operation today. It recently targeted Brazilian petroleum giant Petrobras and Under Armour, the global activewear and footwear brand.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
The ransomware gang, believed to be Russia-linked, was first identified in 2021. It made headlines after the October 2022 attack on the American telecommunications behemoth AT&T. At the time, Everest said it had access to AT&T’s entire corporate network.
According to Ransomware.live, Everest has victimized over 116 organizations in the past 12 months, making it one of the most notorious cybercrime cartels currently operating.