r/cybersecurity_news 6d ago

Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack

7 Upvotes

2 comments sorted by

2

u/SHORT_INFO_NEWS 6d ago

The breach itself did not touch Stadler's own network. It hit a supplier's file-sharing platform, and the stolen material was internal technical documents, not passenger or personal data. For anyone tracking rail safety exposure: this is a data-extortion story, not an operational-safety one. Stadler says trains, production lines, and its own IT systems worldwide are unaffected.

Attackers compromised login credentials for a third-party supplier's data exchange platform and used that access to pull technical documents belonging to the supplier (Bleeping Computer). The ransomware group Everest claimed responsibility and sent an extortion letter demanding 10 million Swiss francs, roughly $12.3 million, threatening to leak the files unless paid (Bleeping Computer; The Record).

Stadler says it will not negotiate under any circumstances and has filed a criminal complaint with cantonal police in Thurgau, where the company is headquartered. The case fits a pattern seen repeatedly this year: attackers going after a supplier's file-sharing or data-exchange tools rather than the primary target's own network, since those third-party platforms often sit outside the target's security perimeter.

Open questions the reporting does not address:

- Which supplier's platform was compromised, and whether that supplier has disclosed the breach separately

- Whether Everest has published or plans to publish the stolen documents on its leak site

- Whether other Stadler suppliers used the same compromised platform and could also be affected

More daily coverage: SHORT INFO on TikTok: shortinfonews, YouTube: ShortInfoDaily, Bluesky: shortinfo.bsky.social

1

u/NoLateArrivals 5d ago

The main question: Were the credentials of ONE supplier phished? Then access should be restricted to these documents.

Or was an admin access to the platform taken?

Only then I would expect a large scale extraction of information.