Everest Ransomware Gang Breaches Stadler Rail Supplier Data Exchange Platform, Demands $12.3M (CHF 10M) Ransom

Everest Ransomware Gang Breaches Stadler Rail Supplier Data (TL-2026-1642), also tracked as Stadler Rail Supplier Data Exchange Breach, is a medium-severity ransomware operation, first published 2026-07-22. It is attributed to Everest with high confidence, affects Stadler Rail Supplier Data Exchange / Trading Platform, maps to 29 MITRE ATT&CK techniques (T1003.001, T1018, T1020), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-1642

Threat ID
TL-2026-1642
Also known as
Stadler Rail Supplier Data Exchange Breach
Severity
MEDIUM
Status
ACTIVE
Category
RANSOMWARE
First published
2026-07-22
Last reviewed
2026-07-22
Attribution
Everest
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
transport, manufacturing, rail, government administration, health, aviation, retail, legal, education, finance, logistics, technology
Target regions
Europe, North America, Asia, switzerland
Detection rules
9
Indicators of compromise
20

Malware and tooling in Everest Ransomware Gang Breaches Stadler Rail Supplier Data

Malware and tooling: Everest Ransomware, Cobalt Strike, Everest Tor-based leak/extortion site, Mimikatz, Rclone - S1040, WinRAR, WinSCP

The Everest ransomware/extortion gang compromised login credentials for a supplier-facing data exchange platform used by Swiss rail manufacturer Stadler Rail, stealing non-sensitive technical documentation and demanding $12.3 million (CHF 10 million). Stadler publicly refused to pay, filed a criminal complaint with Thurgau cantonal police, and confirmed its IT systems, production lines, and in-service rail vehicles worldwide were unaffected.

How Everest Ransomware Gang Breaches Stadler Rail Supplier Data works

In mid-July 2026, the Everest ransomware/data-extortion group gained unauthorized access to a third-party data exchange (trading) platform used by Stadler Rail — an 18,000-employee Swiss rolling-stock manufacturer with roughly $4.9B in annual revenue and eight production facilities worldwide — to share design documentation and component specifications with one of its suppliers. Public reporting is consistent that the initial access vector was compromised login credentials for that shared platform rather than a vulnerability in Stadler's own network; no CVE has been disclosed, and Stadler has stated its internal IT systems were not compromised and continued to operate normally. Everest exfiltrated a set of technical files described by Stadler as containing no personal data and posing no bearing on railway safety, then demanded $12.3 million (CHF 10 million) not to leak the material, publishing the claim on its Tor-based leak/extortion site consistent with its established double-extortion (now largely pure-extortion/IAB-hybrid) business model. Stadler publicly rejected the demand — "Stadler will not pay any ransom under any circumstances and is therefore not susceptible to extortion" — and filed a criminal complaint with the Thurgau cantonal police (the canton where Stadler is headquartered, in Bussnang, Switzerland). This is Stadler's second publicly known cyber incident, following a 2020 malware/data-theft intrusion.

Everest (active since December 2020, ransomware code lineage traced to EverBe 2.0 with more recent code-level overlap noted with BlackByte) has evolved from double-extortion ransomware deployment into a primarily data-theft/extortion and initial-access-broker (IAB) operation, increasingly monetizing compromised access itself rather than always deploying an encryptor. The group has claimed victims across government, healthcare, manufacturing, aviation (Collins Aerospace, Dublin Airport passenger data), retail (Under Armour), legal, education, finance, logistics, and technology-reseller sectors across North America, Europe, and Asia, and geo-fences its encryptor against CIS-locale systems (Russian, Ukrainian, Kazakh, Belarusian), a strong indicator of Russian/CIS-region operator affiliation. This incident fits Everest's established initial-access pattern — compromising credentials for a trusted third-party platform (a supplier/partner data-exchange system) rather than attacking the primary target directly — extending Everest's supply-chain/third-party-platform targeting into the rail/industrial-manufacturing sector.

MITRE ATT&CK techniques used in TL-2026-1642

Credential Access

T1003.001 LSASS Memory; T1552 Unsecured Credentials

Discovery

T1018 Remote System Discovery; T1046 Network Service Discovery; T1082 System Information Discovery

Exfiltration

T1020 Automated Exfiltration; T1567 Exfiltration Over Web Service

Lateral Movement

T1021 Remote Services; T1021.001 Remote Desktop Protocol

Defense Evasion

T1027 Obfuscated Files or Information; T1055 Process Injection; T1070 Indicator Removal

Collection

T1074 Data Staged; T1560.001 Archive via Utility

Initial Access

T1078 Valid Accounts; T1078.001 Default Accounts; T1190 Exploit Public-Facing Application; T1199 Trusted Relationship; T1566.001 Spearphishing Attachment

Command and Control

T1090.003 Multi-hop Proxy; T1105 Ingress Tool Transfer

defense-impairment

T1112 Modify Registry; T1685 Disable or Modify Tools

Impact

T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1657 Financial Theft

Privilege Escalation

T1548 Abuse Elevation Control Mechanism

Resource Development

T1583.004 Server

Affected products and versions in Everest Ransomware Gang Breaches Stadler Rail Supplier Data

  • Stadler Rail — Supplier Data Exchange / Trading Platform
    Vulnerable versions: N/A - credential compromise, not a software vulnerability

Remediation for Everest Ransomware Gang Breaches Stadler Rail Supplier Data

Immediate actions

  • Rotate and enforce MFA on all credentials for third-party/supplier data exchange and trading platforms
  • Audit access logs on shared supplier portals for anomalous logins, bulk downloads, or off-hours access
  • Notify and coordinate with affected suppliers/partners connected to the compromised data exchange platform
  • Engage law enforcement (as Stadler did via Thurgau cantonal police) and preserve forensic evidence
  • Review and restrict what technical documentation categories are shared via third-party exchange platforms

Workarounds

  • Temporarily disable or tightly restrict external access to the affected data exchange platform pending credential rotation
  • Require re-authentication with MFA for any session accessing supplier/partner data exchange systems

Longer-term hardening

  • Implement Zero Trust segmentation between supplier-facing data exchange platforms and core enterprise/OT networks
  • Deploy phishing-resistant MFA (FIDO2/hardware tokens) for all third-party and supplier-facing portal accounts
  • Establish continuous monitoring and DLP on outbound data flows from shared exchange platforms
  • Conduct third-party/supplier security risk assessments and require breach-notification SLAs in supplier contracts
  • Deploy EDR with credential-dumping and LSASS-access detection across environments handling supplier data exchange

Weaknesses (CWE) in Everest Ransomware Gang Breaches Stadler Rail Supplier Data

CWE-522, CWE-287, CWE-284

Timeline of Everest Ransomware Gang Breaches Stadler Rail Supplier Data

  • Stadler Rail previously disclosed a malware infection and data-theft cyberattack in 2020, unrelated to this Everest incident.
  • Everest ransomware/extortion group first observed active, with code lineage traced to the EverBe 2.0 ransomware family.
  • AttackIQ publishes a technical intelligence summary detailing Everest's ransomware payload characteristics, encryption scheme, and anti-analysis capabilities.
  • Estimated window of initial compromise: Everest gains access to Stadler's supplier data exchange platform via compromised login credentials (mid-July 2026, per public reporting).
  • Everest demands $12.3 million (CHF 10 million) from Stadler Rail not to leak stolen technical data, publicizing the claim via its Tor-based leak site.
  • Railway Gazette International reports Stadler's refusal to pay the SFr10m ransom and confirms normal operation of IT systems and production.
  • Stadler Rail publicly states it will not pay any ransom under any circumstances and confirms it filed a criminal complaint with Thurgau cantonal police.
  • BleepingComputer and multiple outlets publish coverage confirming the breach, ransom amount, Everest attribution, and Stadler's response.

Sources cited for Everest Ransomware Gang Breaches Stadler Rail Supplier Data

Threats related to Everest Ransomware Gang Breaches Stadler Rail Supplier Data

Detection coverage for TL-2026-1642

As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1642 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats