Stadler Rail said a cyberattack targeted a data-exchange platform operated by one of its suppliers after attackers obtained compromised login credentials, allowing access to certain technical data. The company said its own internal IT systems were not breached, production continued normally, and no sensitive personal data was stolen; it also reported that the incident did not create any safety risk and later indicated the situation was under control.
The attackers were identified as the Everest group, which reportedly demanded 10 million Swiss francs in ransom after the data theft. Stadler said it would not pay, filed a criminal complaint, and stated that no confirmed data loss had been established beyond the accessed supplier-platform information.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
On July 21, 2026, reporting indicated Stadler gave the all-clear following the cyberattack. This marked a public statement that the situation had stabilized after the incident.
Stadler publicly refused to pay the 10 million Swiss franc ransom demanded by Everest and said it had filed a criminal complaint. The company also stated that production was continuing normally.
Following the data theft, the Everest cybercriminal group demanded a ransom of 10 million Swiss francs from Stadler. The company said the stolen material did not include sensitive personal data and posed no safety risk.
In mid-July 2026, cybercriminals used compromised login credentials for a data-exchange platform operated by one of Stadler's suppliers to access certain technical data. Stadler said its own internal IT systems were not compromised.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
8 references tracked. Mallory keeps watching after this page renders.
theregister.com
Open sourceteiss.co.uk
Open sourcecyberveille.ch
Open sourcehelpnetsecurity.com
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourceinside-it.ch
Open sourcecyberveille.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.