Everest Ransomware Gang Breaches Stadler Rail Supplier Data Exchange Platform, Demands $12.3M (CHF 10M) Ransom
Everest Ransomware Gang Breaches Stadler Rail Supplier Data (TL-2026-1642), also tracked as Stadler Rail Supplier Data Exchange Breach, is a medium-severity ransomware operation, first published 2026-07-22. It is attributed to Everest with high confidence, affects Stadler Rail Supplier Data Exchange / Trading Platform, maps to 29 MITRE ATT&CK techniques (T1003.001, T1018, T1020), and is covered by 9 detection rules and 20 indicators of compromise.
Key facts for TL-2026-1642
- Threat ID
- TL-2026-1642
- Also known as
- Stadler Rail Supplier Data Exchange Breach
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-07-22
- Last reviewed
- 2026-07-22
- Attribution
- Everest
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- transport, manufacturing, rail, government administration, health, aviation, retail, legal, education, finance, logistics, technology
- Target regions
- Europe, North America, Asia, switzerland
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in Everest Ransomware Gang Breaches Stadler Rail Supplier Data
Malware and tooling: Everest Ransomware, Cobalt Strike, Everest Tor-based leak/extortion site, Mimikatz, Rclone - S1040, WinRAR, WinSCP
The Everest ransomware/extortion gang compromised login credentials for a supplier-facing data exchange platform used by Swiss rail manufacturer Stadler Rail, stealing non-sensitive technical documentation and demanding $12.3 million (CHF 10 million). Stadler publicly refused to pay, filed a criminal complaint with Thurgau cantonal police, and confirmed its IT systems, production lines, and in-service rail vehicles worldwide were unaffected.
How Everest Ransomware Gang Breaches Stadler Rail Supplier Data works
In mid-July 2026, the Everest ransomware/data-extortion group gained unauthorized access to a third-party data exchange (trading) platform used by Stadler Rail — an 18,000-employee Swiss rolling-stock manufacturer with roughly $4.9B in annual revenue and eight production facilities worldwide — to share design documentation and component specifications with one of its suppliers. Public reporting is consistent that the initial access vector was compromised login credentials for that shared platform rather than a vulnerability in Stadler's own network; no CVE has been disclosed, and Stadler has stated its internal IT systems were not compromised and continued to operate normally. Everest exfiltrated a set of technical files described by Stadler as containing no personal data and posing no bearing on railway safety, then demanded $12.3 million (CHF 10 million) not to leak the material, publishing the claim on its Tor-based leak/extortion site consistent with its established double-extortion (now largely pure-extortion/IAB-hybrid) business model. Stadler publicly rejected the demand — "Stadler will not pay any ransom under any circumstances and is therefore not susceptible to extortion" — and filed a criminal complaint with the Thurgau cantonal police (the canton where Stadler is headquartered, in Bussnang, Switzerland). This is Stadler's second publicly known cyber incident, following a 2020 malware/data-theft intrusion.
Everest (active since December 2020, ransomware code lineage traced to EverBe 2.0 with more recent code-level overlap noted with BlackByte) has evolved from double-extortion ransomware deployment into a primarily data-theft/extortion and initial-access-broker (IAB) operation, increasingly monetizing compromised access itself rather than always deploying an encryptor. The group has claimed victims across government, healthcare, manufacturing, aviation (Collins Aerospace, Dublin Airport passenger data), retail (Under Armour), legal, education, finance, logistics, and technology-reseller sectors across North America, Europe, and Asia, and geo-fences its encryptor against CIS-locale systems (Russian, Ukrainian, Kazakh, Belarusian), a strong indicator of Russian/CIS-region operator affiliation. This incident fits Everest's established initial-access pattern — compromising credentials for a trusted third-party platform (a supplier/partner data-exchange system) rather than attacking the primary target directly — extending Everest's supply-chain/third-party-platform targeting into the rail/industrial-manufacturing sector.
MITRE ATT&CK techniques used in TL-2026-1642
Credential Access
T1003.001 LSASS Memory; T1552 Unsecured Credentials
Discovery
T1018 Remote System Discovery; T1046 Network Service Discovery; T1082 System Information Discovery
Exfiltration
T1020 Automated Exfiltration; T1567 Exfiltration Over Web Service
Lateral Movement
T1021 Remote Services; T1021.001 Remote Desktop Protocol
Defense Evasion
T1027 Obfuscated Files or Information; T1055 Process Injection; T1070 Indicator Removal
Collection
T1074 Data Staged; T1560.001 Archive via Utility
Initial Access
T1078 Valid Accounts; T1078.001 Default Accounts; T1190 Exploit Public-Facing Application; T1199 Trusted Relationship; T1566.001 Spearphishing Attachment
Command and Control
T1090.003 Multi-hop Proxy; T1105 Ingress Tool Transfer
defense-impairment
T1112 Modify Registry; T1685 Disable or Modify Tools
Impact
T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1657 Financial Theft
Privilege Escalation
T1548 Abuse Elevation Control Mechanism
Resource Development
Affected products and versions in Everest Ransomware Gang Breaches Stadler Rail Supplier Data
- Stadler Rail — Supplier Data Exchange / Trading Platform
Vulnerable versions: N/A - credential compromise, not a software vulnerability
Remediation for Everest Ransomware Gang Breaches Stadler Rail Supplier Data
Immediate actions
- Rotate and enforce MFA on all credentials for third-party/supplier data exchange and trading platforms
- Audit access logs on shared supplier portals for anomalous logins, bulk downloads, or off-hours access
- Notify and coordinate with affected suppliers/partners connected to the compromised data exchange platform
- Engage law enforcement (as Stadler did via Thurgau cantonal police) and preserve forensic evidence
- Review and restrict what technical documentation categories are shared via third-party exchange platforms
Workarounds
- Temporarily disable or tightly restrict external access to the affected data exchange platform pending credential rotation
- Require re-authentication with MFA for any session accessing supplier/partner data exchange systems
Longer-term hardening
- Implement Zero Trust segmentation between supplier-facing data exchange platforms and core enterprise/OT networks
- Deploy phishing-resistant MFA (FIDO2/hardware tokens) for all third-party and supplier-facing portal accounts
- Establish continuous monitoring and DLP on outbound data flows from shared exchange platforms
- Conduct third-party/supplier security risk assessments and require breach-notification SLAs in supplier contracts
- Deploy EDR with credential-dumping and LSASS-access detection across environments handling supplier data exchange
Weaknesses (CWE) in Everest Ransomware Gang Breaches Stadler Rail Supplier Data
CWE-522, CWE-287, CWE-284
Timeline of Everest Ransomware Gang Breaches Stadler Rail Supplier Data
- Stadler Rail previously disclosed a malware infection and data-theft cyberattack in 2020, unrelated to this Everest incident.
- Everest ransomware/extortion group first observed active, with code lineage traced to the EverBe 2.0 ransomware family.
- AttackIQ publishes a technical intelligence summary detailing Everest's ransomware payload characteristics, encryption scheme, and anti-analysis capabilities.
- Estimated window of initial compromise: Everest gains access to Stadler's supplier data exchange platform via compromised login credentials (mid-July 2026, per public reporting).
- Everest demands $12.3 million (CHF 10 million) from Stadler Rail not to leak stolen technical data, publicizing the claim via its Tor-based leak site.
- Railway Gazette International reports Stadler's refusal to pay the SFr10m ransom and confirms normal operation of IT systems and production.
- Stadler Rail publicly states it will not pay any ransom under any circumstances and confirms it filed a criminal complaint with Thurgau cantonal police.
- BleepingComputer and multiple outlets publish coverage confirming the breach, ransom amount, Everest attribution, and Stadler's response.
Sources cited for Everest Ransomware Gang Breaches Stadler Rail Supplier Data
- Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
- Cyberattackers demand CHF10m from Swiss train maker Stadler
- Stadler refuses to pay SFr10m cyberattack ransom
- Stadler Rail Rejects $12.3 Million Ransom After Supplier Breach
- Hackers Demand CHF 10 Million Ransom From Stadler Rail
- Hackers demand CHF 10 million from Stadler
- Stadler Rail refuses to pay $12.3 million ransom after ransomware attack
- Ransomware Spotlight: Everest's Focus on Initial Access
- Everest Ransomware Group Increases Initial Access Broker Activity
- Everest Ransomware Group – Threat Actor Profile
- Everest Ransomware (AttackIQ technical intelligence summary)
- Everest Ransomware Group Claims Theft of 1.5 Million Passenger Records from Dublin Airport
- Under Armour Customer Data Breach 2025: Technical Analysis of Everest Ransomware Attack
- Everest Ransomware Hits Collins Aerospace & European Airports
Threats related to Everest Ransomware Gang Breaches Stadler Rail Supplier Data
- Everest Ransomware Group Demands $12.3M from Stadler Rail via Third-Party Supplier Breach
- Everest Ransomware: Triple Extortion via Encryption, Access Brokering, and Insider Recruitment
- Everest Ransomware Gang Extorts Stadler Rail via Compromised Supplier Credentials, CHF 10M Demand Refused
- GodDamn Ransomware (Hyadina) — Third Rebrand from Monster/Beast, Deploys Signed PoisonX Kernel Driver
- FortiBleed Credential-Harvesting Campaign Against 430,000 FortiGate Firewalls Feeds INC Ransom and Lynx Ransomware Operations
- AI-Generated Extortion: Fabricated Data-Leak Sites 0APT and ALP-001 Impersonate Ransomware Groups
Detection coverage for TL-2026-1642
As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1642 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.