Everest Ransomware Gang Breaches Stadler Rail Supplier Data Exchange Platform, Demands $12.3M (CHF 10M) Ransom — Threadlinqs Intelligence
As of 2026-07-22, Everest Ransomware Gang Breaches Stadler Rail Supplier Data Exchange Platform, Demands $12.3M (CHF 10M) Ransom is a medium-severity ransomware threat attributed to Everest, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1642 · Severity: MEDIUM · Status: ACTIVE · Category: RANSOMWARE
Attribution: Everest · FINANCIAL
The Everest ransomware/extortion gang compromised login credentials for a supplier-facing data exchange platform used by Swiss rail manufacturer Stadler Rail, stealing non-sensitive technical
In mid-July 2026, the Everest ransomware/data-extortion group gained unauthorized access to a third-party data exchange (trading) platform used by Stadler Rail — an 18,000-employee Swiss rolling-stock manufacturer with roughly $4.9B in annual revenue and eight production facilities worldwide — to share design documentation and component specifications with one of its suppliers. Public reporting is consistent that the initial access vector was compromised login credentials for that shared platform rather than a vulnerability in Stadler's own network; no CVE has been disclosed, and Stadler has stated its internal IT systems were not compromised and continued to operate normally. Everest exfiltrated a set of technical files described by Stadler as containing no personal data and posing no bearing on railway safety, then demanded $12.3 million (CHF 10 million) not to leak the material, publishing the claim on its Tor-based leak/extortion site consistent with its established double-extortion (now largely pure-extortion/IAB-hybrid) business model. Stadler publicly rejected the demand — "Stadler will not pay any ransom under any circumstances and is therefore not susceptible to extortion" — and filed a criminal complaint with the Thurgau cantonal police (the canton where Stadler is headquartered, in Bussnang, Switzerland). This is Stadler's second publicly known cyber incident, following a 2020 malware/data-theft intrusion.
Everest (active since December 2020, ransomware code lineage traced to EverBe 2.0 with more recent code-level overlap noted with BlackByte) has evolved from double-extortion ransomware deployment into a primarily data-theft/extortion and initial-access-broker (IAB) operation, increasingly monetizing compromised access itself rather than always deploying an encryptor. The group has claimed victims across government, healthcare, manufacturing, aviation (Collins Aerospace, Dublin Airport passenger data), retail (Under Armour), legal, education, finance, logistics, and technology-reseller sectors across North America, Europe, and Asia, and geo-fences its encryptor against CIS-locale systems (Russian, Ukrainian, Kazakh, Belarusian), a strong indicator of Russian/CIS-region operator affiliation. This incident fits Everest's established initial-access pattern — compromising credentials for a trusted third-party platform (a supplier/partner data-exchange system) rather than attacking the primary target directly — extending Everest's supply-chain/third-party-platform targeting into the rail/industrial-manufacturing sector.
Weaknesses (CWE)
CWE-522, CWE-287, CWE-284
Target sectors: transport, manufacturing, rail, government administration, health, aviation, retail, legal, education, finance, logistics, technology
Target regions: Europe, North America, Asia, switzerland
Detections & IOCs
As of 2026-07-24, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, MEDIUM, threat intelligence, cybersecurity, T1078, T1078.001, T1199, T1190, T1566.001, T1003.001, T1552, T1018, T1046, T1082