ctipilot.ch

Stadler Rail supplier-platform breach

incident · incident:stadler-rail-everest-supplier-breach-2026

Everest ransomware group compromised a data-exchange platform Stadler Rail (Swiss rolling-stock manufacturer, Thurgau) shares with a supplier and demanded a CHF 10 million ransom; Stadler refused to pay, filed a criminal complaint, and reports its own IT and worldwide production unaffected with no security-relevant or personal data stolen (swissinfo.ch, Swiss IT Magazine, 2026-07-21).

Coverage timeline
1
first 2026-07-22 → last 2026-07-22
Peak priority
notable
1 notable
Sources cited
3
3 hosts
Sections touched
1
active-threats
Co-occurring entities
1
see Related entities below
ATT&CK techniques
1
pinned v19.1 · see below

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1199Trusted Relationship×1

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-07-22/everest-ransomware-stadler-rail-supplier-platform-breach · ATT&CK page ↗

Story timeline

  1. 2026-07-22Everest ransomware breaches a Stadler Rail supplier data-exchange platform, demands CHF 10 million — the Swiss rail manufacturer refuses to pay
    active-threatsEverest reaches Stadler Rail through a supplier's data-exchange platform, not Stadler's own perimeter

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

attributed to

Where this entity is cited

  • active-threats1

Source distribution

  • halcyon.ai1 (33%)
  • itmagazine.ch1 (33%)
  • swissinfo.ch1 (33%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Stadler Rail supplier-platform breach (1)

2026-07-22 · view entry permalink →

NOTABLENATOB2

Everest ransomware breaches a Stadler Rail supplier data-exchange platform, demands CHF 10 million — the Swiss rail manufacturer refuses to pay

Stadler Rail disclosed on 2026-07-21 that unauthorised parties gained access, in mid-July, to a data-exchange platform Stadler uses with an (unnamed) supplier, and that the Everest ransomware/extortion group claimed the intrusion and demanded a CHF 10 million ransom (swissinfo.ch, 2026-07-21). Stadler states it does not pay ransoms under any circumstances, has filed a criminal complaint with Thurgau cantonal police, and reports that its own IT systems were unharmed, no security-relevant or personal data was stolen, and worldwide rail-vehicle production and in-service fleets are unaffected — the accessed information belonged to the supplier and is described as not security-relevant (Swiss IT Magazine, 2026-07-21).

Everest is a Russian-speaking, closed-group double-extortion operation that emerged in December 2020, with a code-level connection to the BlackByte ransomware family; it has run hybrid Initial Access Broker services since November 2021 and a corporate-insider recruitment programme offering cash/profit-sharing since October 2023, and its documented infection vectors are internet-exposed RDP without MFA, vulnerable VPN endpoints, and credentials bought from other brokers (Halcyon, 2025-11-19). Per the same profile the group claimed, in October 2025, attacks on critical infrastructure including a European national electricity transmission operator, aviation systems affecting multiple European airports (Heathrow, Brussels and Berlin), and telecommunications networks — recurring targeting of the European critical-infrastructure and transport space, though those victim claims are the group's own leak-site assertions and are unconfirmed by the named organisations.

Ein von der cyberkriminellen Everest Group gefordertes Lösegeld in Höhe von zehn Millionen Franken bezahlte die Firma laut Mitteilung nicht

Die Produktion laufe aktuell weltweit normal weiter

swissinfo.ch 2026-07-21
incident22 Jul 04:34Zmulti-sourceOpen finding ↗