CTIPilot
← Back to Daily brief 2026-07-22
NOTABLEupdatedNATOB2incident

Everest ransomware breaches a Stadler Rail supplier data-exchange platform, demands CHF 10 million, the Swiss rail manufacturer refuses to pay

Everest reaches Stadler Rail through a supplier's data-exchange platform, not Stadler's own perimeter

Analysis

Stadler Rail disclosed on 2026-07-21 that unauthorised parties gained access, in mid-July, to a data-exchange platform Stadler uses with an (unnamed) supplier, and that the Everest ransomware/extortion group claimed the intrusion and demanded a CHF 10 million ransom (swissinfo.ch, 2026-07-21). Stadler states it does not pay ransoms under any circumstances, has filed a criminal complaint with Thurgau cantonal police, and reports that its own IT systems were unharmed, no security-relevant or personal data was stolen, and worldwide rail-vehicle production and in-service fleets are unaffected; the accessed information belonged to the supplier and is described as not security-relevant (Swiss IT Magazine, 2026-07-21).

Everest is a Russian-speaking, closed-group double-extortion operation that emerged in December 2020, with a code-level connection to the BlackByte ransomware family; it has run hybrid Initial Access Broker services since November 2021 and a corporate-insider recruitment programme offering cash/profit-sharing since October 2023, and its documented infection vectors are internet-exposed RDP without MFA, vulnerable VPN endpoints, and credentials bought from other brokers (Halcyon, 2025-11-19). Per the same profile the group claimed, in October 2025, attacks on critical infrastructure including a European national electricity transmission operator, aviation systems affecting multiple European airports (Heathrow, Brussels and Berlin), and telecommunications networks, recurring targeting of the European critical-infrastructure and transport space, though those victim claims are the group's own leak-site assertions and are unconfirmed by the named organisations.

Cited evidence

Ein von der cyberkriminellen Everest Group gefordertes Lösegeld in Höhe von zehn Millionen Franken bezahlte die Firma laut Mitteilung nicht

Die Produktion laufe aktuell weltweit normal weiter

swissinfo.ch 2026-07-21

According to the threat actor, which was first flagged by threat-intelligence tracker HackManac, the data breach yielded a 201 GB FTP archive holding more than 271,000 files.

Everest claims the compromised data touches projects linked to several high-profile operators, including Deutsche Bahn, Merseytravel, Westbahn, and MTR, alongside other unnamed clients. If validated, exposure of engineering documentation and system configurations tied to these operators raises concerns around downstream risk to connected railway infrastructure.

TechNadu 2026-07-29

Stadler hat durch den Vorfall von Mitte Juli 2026 keine Daten verloren. Der Zugriff auf diese spezifischen, technischen Daten erfolgte über kompromittierte Zugangsdaten einer Datenaustausch-Plattform.

Stadler Rail 2026-07-21

Updates1

Update

The earlier entry recorded Everest compromising a data-exchange platform Stadler Rail shares with a supplier, a CHF 10 million demand, and Stadler's refusal to pay. The extortion has now moved to its next stage: Everest has published the data (Inside IT Switzerland, 2026-07-30). What is new beyond that fact is a claim about who else is in the archive, and it needs handling with care.

TechNadu reports a 201 GB archive holding more than 271,000 files, attributing the figures to the actor itself via a threat-intelligence tracker that flagged the listing, with the content described as railway software, CCTV footage, engineering documentation and configuration files. It further reports that Everest claims the data touches projects linked to Deutsche Bahn, Merseytravel, Westbahn and MTR, and appends its own conditional, "if validated," exposure of engineering documentation and system configurations tied to these operators would raise downstream risk to connected railway infrastructure (TechNadu, 2026-07-29). That hedge is the correct reading. These are an extortion group's assertions about the value of what it stole, relayed through one outlet, and none of the four named operators has confirmed anything. TechNadu also notes the odd operational detail that Everest claimed the attack but did not list Stadler on its leak site, so the archive appears to have been dropped outside the group's normal publication channel.

Stadler's own position has not moved. Its media release, first published on 21 July and last revised on 23 July according to its content-management metadata, states that Stadler lost no data in the mid-July 2026 incident and that access to the specific technical data involved was obtained through compromised credentials for a data-exchange platform; it records the CHF 10 million demand, the refusal to pay, and a criminal complaint filed with the Thurgau cantonal police (Stadler Rail, 2026-07-21). The release does not confirm, deny or acknowledge the publication event, it predates it. So the current state is a victim statement scoped to "no security-relevant or personal data" standing beside an attacker claim of a 201 GB archive naming four third-party operators, with nothing yet reconciling them.

That gap is the pattern worth flagging rather than the file count. Two Swiss and European public-sector incidents this month followed the same arc, an early, narrow "not affected" characterisation, followed by a leak or an authority report that contradicted it. This one has not reached that point, and it may not; Stadler's statement may hold up entirely. But an early scoping statement issued before an attacker publishes is a hypothesis about what was taken, and it is being treated by readers as a finding.

Sources6

Revision history

  1. Published 2026-07-22T0409Z-intel
  2. Update 2026-07-31T0409Z-intel

    Everest has published data it says came from the data-exchange platform Stadler Rail shares with a supplier, turning the CHF 10 million extortion Stadler refused into an actual disclosure event. TechNadu, relaying a threat-intelligence tracker's post of Everest's own listing, reports a 201 GB archive of more than 271,000 files and says Everest claims the material touches projects tied to Deutsche Bahn, Merseytravel, Westbahn and MTR; claims none of those operators or Stadler has confirmed, and which no second outlet independently reports. Stadler's own media release, first published 21 July and last revised 23 July, still states no security-relevant or personal data was taken and does not address the publication at all. The access path is unchanged and is the transferable part: compromised credentials for a shared supplier data-exchange platform, not Stadler's own perimeter.

    Changed: evidence regions sources techniques body

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.