Back to Home
Security

Swiss train maker tells ransomware crooks to get off at the next stop

Stadler refuses $12.3 demand after thieves swipe technical data through supplier platform

t
tech4you AI
July 23, 20261 min read
Share

Security

Swiss train maker tells ransomware crooks to get off at the next stop

Stadler refuses $12.3M demand after thieves swipe technical data through supplier platform

Swiss rail manufacturer Stadler Rail says it refused a CHF 10 million ($12.3 million) ransom demand after the Everest ransomware gang compromised one of its suppliers.

Stadler will not pay, and based on its account of events, the company appears to have got off lightly. It stated that "no security-relevant data [was] affected" in the breach, which was limited to "technical information from a supplier."

According to its announcement, "no relevant personal data was stolen," and the incident had no impact on the functioning of its rolling stock (train and tram carriages) or its global production lines.

The attackers accessed the technical data through a "data exchange platform" Stadler used with the unnamed supplier, authenticating with compromised login credentials.

"Stadler's IT systems were not compromised and remained intact," the company said.

At the time of writing, Stadler does not appear on Everest's data leak site (DLS), nor has the swiped technical data been leaked. Stadler's absence from the extortion group's website is unusual.

The typical cyber extortion playbook involves the crooks first notifying victims that data has been stolen and/ or encrypted, then issuing their demand and threat to leak data if the ransom is unpaid. 

Failure to meet the deadline - or refuse outright, as Stadler did - typically lands the victim organization a spot on the extortionist's DLS.

That's often when a second countdown timer begins. Criminals typically offer victims another few days to realize they are not bluffing and will leak the stolen data if a fee isn't paid. If they pay, victims are scrubbed from the DLS. If they don't, their data is leaked. That's the usual playbook.

However, for a victim to both refuse to pay a ransom and not appear on the gang's DLS is an oddity.

Everest, a Russian-speaking cybercrime group, has operated since circa December 2020 and claimed attacks on sportswear giant Under Armour, Mailchimp, AT&T, and Collins Aerospace, to name just a few.

It's dabbled in both encryptionless extortion and double extortion, and has branched out into initial access brokering and recruiting corporate insiders. ®


Originally published on The Register

Swiss train maker tells ransomware crooks to get off at the next stop | tech4you