Swiss rail manufacturer Stadler Rail said it will not pay a 10 million Swiss franc, or about $12.3 million, demand from the ransomware and extortion group Everest after technical documents were taken from a supplier’s file-sharing platform.
Stadler said Tuesday that the mid-July incident did not breach its own systems. The company said its production sites remain operational and that the incident has no effect on trains already running around the world.
The mechanics, as described by Stadler, are a familiar weak point in corporate security: attackers obtained credentials for a data exchange platform used by a third-party supplier. With that access, they copied technical documents belonging to the supplier. Stadler said its own data was not stolen and that no relevant personal information was taken.
Everest claimed responsibility in an extortion letter, according to Stadler. The company said it filed a criminal complaint and will not negotiate with the attackers.
“Under no circumstances will Stadler pay a ransom and therefore cannot be extorted,” the company said in its statement.
A supplier breach, not a factory shutdown
Stadler is one of Europe’s major rail equipment makers. The Switzerland-based company builds trains, trams, metro cars and locomotives for operators worldwide. It is publicly traded, employs about 18,000 people and generates more than $4.9 billion in annual revenue.
The company did not say whether Everest had started publishing any of the stolen supplier files. Recorded Future News reported that, as of Thursday, Stadler did not appear on Everest’s dark web leak site. Stadler declined to comment further on the incident, according to Recorded Future News.
The case is another reminder that a vendor portal can be enough for an extortion crew. The attacker does not need to knock over the train maker’s core network if a contractor account leads to material the company would rather not see online. Stadler’s statement draws that line carefully: supplier documents were taken, Stadler systems were not affected, and rail operations were not disrupted.
Stadler has been here before
This is the second known extortion attempt against Stadler in recent years. In 2020, the company said unknown attackers broke into some of its systems, stole internal files and demanded roughly $6 million in bitcoin. Stadler refused to pay then as well.
After that refusal, the attackers published samples of stolen data, which reportedly included financial and administrative documents. Stadler maintained its position against negotiating even after the leak.
Everest is a Russian-speaking ransomware and extortion group active since at least 2020. The group has targeted organizations in critical infrastructure sectors including energy, transportation and telecommunications.
Last year, Everest claimed an attack involving an external file transfer system used by Svenska kraftnät, Sweden’s state-owned electricity grid operator. That incident did not disrupt power supplies, according to the reporting cited by Recorded Future News.
Everest also recently claimed responsibility for a breach tied to a contractor for Japanese automaker Nissan. Nissan said systems operated by the third-party vendor were compromised, but said it found no evidence that its own customer data had been accessed.
This story draws on original reporting from The Record.