01Summary
In mid-July 2026 attackers compromised a data-exchange platform used by Stadler and one of its suppliers and took technical information. Everest sent an extortion letter demanding about CHF 10 million (about US$12.3 million). Stadler said it was "not susceptible to extortion", refused to pay and filed a criminal complaint. It said internal IT, production and railway operations were unaffected and no security-critical or relevant personal data was exposed.
02Victims and impact
Countries affected
- Switzerland
03Data exposed
Data types
- Supplier technical information
04Timeline
- 2026-07-15Supplier data-exchange platform compromised (mid-July).
- 2026-07-21Stadler publicly refuses the ransom.
05Legal
Criminal complaint filed with Swiss authorities.
06Disclosure and media
Publishing organisations
- Railway Gazette
- The Record
- The Register
- Help Net Security
07Sources
References
- [1]The Record: https://therecord.media/stadler-refuses-everest-ransom-demand
- [2]Railway Gazette: https://www.railwaygazette.com/stadler/2026/07/21/stadler-refuses-to-pay-sfr10m-cyberattack-ransom/









