ctipilot.ch
← Back to the live brief
NOTABLENATOB2incident

Everest ransomware breaches a Stadler Rail supplier data-exchange platform, demands CHF 10 million — the Swiss rail manufacturer refuses to pay

discovered 2026-07-22 04:34 UTCrun 2026-07-22T0409Z-intel3 sourcesmulti-source

Stadler Rail disclosed on 2026-07-21 that unauthorised parties gained access, in mid-July, to a data-exchange platform Stadler uses with an (unnamed) supplier, and that the Everest ransomware/extortion group claimed the intrusion and demanded a CHF 10 million ransom (swissinfo.ch, 2026-07-21). Stadler states it does not pay ransoms under any circumstances, has filed a criminal complaint with Thurgau cantonal police, and reports that its own IT systems were unharmed, no security-relevant or personal data was stolen, and worldwide rail-vehicle production and in-service fleets are unaffected — the accessed information belonged to the supplier and is described as not security-relevant (Swiss IT Magazine, 2026-07-21).

Everest is a Russian-speaking, closed-group double-extortion operation that emerged in December 2020, with a code-level connection to the BlackByte ransomware family; it has run hybrid Initial Access Broker services since November 2021 and a corporate-insider recruitment programme offering cash/profit-sharing since October 2023, and its documented infection vectors are internet-exposed RDP without MFA, vulnerable VPN endpoints, and credentials bought from other brokers (Halcyon, 2025-11-19). Per the same profile the group claimed, in October 2025, attacks on critical infrastructure including a European national electricity transmission operator, aviation systems affecting multiple European airports (Heathrow, Brussels and Berlin), and telecommunications networks — recurring targeting of the European critical-infrastructure and transport space, though those victim claims are the group's own leak-site assertions and are unconfirmed by the named organisations.

Ein von der cyberkriminellen Everest Group gefordertes Lösegeld in Höhe von zehn Millionen Franken bezahlte die Firma laut Mitteilung nicht

Die Produktion laufe aktuell weltweit normal weiter

swissinfo.ch 2026-07-21

ATT&CK mapping

1 technique mapped from the cited reporting · MITRE ATT&CK v19.1

Initial Access TA0001
T1199Trusted Relationship

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.