Stadler Rail, the Swiss train manufacturer whose vehicles run on rail networks across Europe and beyond, has refused a 10 million Swiss franc ransom demand, roughly $12.3 million, from the Everest ransomware gang and filed a criminal complaint with Swiss police rather than negotiate.
The company confirmed it was breached in mid-July 2026 through a data-exchange platform it shares with one of its suppliers, a detail that places the incident within a growing pattern of attacks that reach large, well-defended manufacturers not by breaching their own perimeter directly, but by compromising a smaller partner or shared system with weaker controls sitting between them.
What Everest actually stole
Stadler said the data accessed through the breach was technical information that was not security-relevant and did not include personally identifiable information. The company was explicit that rail vehicles in service and its own production operations were unaffected throughout the incident, a distinction that matters for a company whose products are safety-critical transportation infrastructure used by millions of passengers.
The Everest ransomware gang, which security researchers say emerged around 2020, has increasingly shifted its business model away from encrypting victim networks and toward pure data-theft extortion, stealing information and threatening to publish it rather than locking systems and demanding payment for a decryption key. That shift reflects a broader trend across the ransomware ecosystem in 2026, as encryption-based attacks have become easier for well-prepared organizations to recover from using backups, pushing extortion groups toward threats that backups alone cannot neutralize.
A flat refusal, on principle
Stadler's public statement left no room for negotiation: "Stadler will not pay any ransom under any circumstances and is therefore not susceptible to extortion." The company filed a criminal complaint with police in the Swiss canton of Thurgau, where Stadler is headquartered, rather than engaging with the attackers directly.
As of the most recent reporting, Stadler had not appeared on Everest's dark-web extortion leak site, where the group typically publishes stolen data from victims who decline to pay, though that could change if the group follows through on its threat. Stadler had previously disclosed a separate cybersecurity incident in 2020, making this the company's second publicly acknowledged breach in six years.
Why the supplier angle matters
Stadler Rail employs roughly 18,000 people across eight production facilities and six engineering sites worldwide, with annual revenue exceeding $4.9 billion, resources that would typically support a mature internal security program. The breach nonetheless originated through a shared data-exchange platform connected to a supplier, illustrating a persistent weak point even for well-resourced manufacturers: the security of a shared integration point is only as strong as the weaker of the two organizations connected to it.
For rail operators, manufacturers and other critical-infrastructure-adjacent companies watching the incident, the practical lesson is less about Stadler's own defenses, which appear to have held, and more about the growing need to treat supplier-facing data platforms as part of an organization's own attack surface rather than someone else's problem. A ransomware gang does not need to breach a well-defended target directly if it can walk in through a door that target built to connect with a less well-defended partner.
A ransom refusal that held
Whether Stadler's refusal ultimately proves costly, if Everest follows through and publishes stolen data, or vindicated, if the group moves on without further action, will not be clear for some time. But the company's public position reflects a stance security agencies including the FBI and Europol have pushed for years: paying ransomware demands funds future attacks and offers no guarantee stolen data will actually be deleted, even when a ransom is paid in full.

