Swiss train maker tells ransomware crooks to get off at the next stop

← Back to the feed

Swiss train maker tells ransomware crooks to get off at the next stop

The Register · 4 hours ago

Swiss train manufacturer Stadler Rail has refused to pay a CHF 10 million ($12.3 million) ransom demand made by the Everest ransomware gang after attackers stole technical data via a compromised supplier's login credentials. The company says the breach did not compromise its own IT systems, involved no personal data, and had no effect on the production or operation of its trains and trams, meaning it appears to have escaped largely unscathed despite the significant ransom sought.

The attackers gained access through a data exchange platform Stadler used with an unnamed supplier, rather than breaching Stadler's own network directly. Notably, despite refusing to pay, Stadler has not appeared on Everest's data leak site and the stolen data has not been published, which is unusual given that extortion gangs typically publish victims' data or list them on leak sites as punishment for non-payment. Everest, a Russian-speaking cybercrime group active since around December 2020, has previously claimed attacks on Under Armour, Mailchimp, AT&T and Collins Aerospace, and engages in both encryption-based and encryptionless extortion.

  • Stadler Rail refused Everest gang's $12.3m ransom demand
  • Breach hit a supplier's platform, not Stadler's own systems
  • No data leaked yet, an unusual outcome after refusal to pay

Cybersecurity Technology

Read the full article at the source →