Stadler has rejected a CHF 10 million ransom demand after cybercriminals accessed supplier technical data, while the manufacturer says its systems and trains remain unaffected.

Stadler Salt Lake City expansion opens in Utah
Photo: Stadler

Compromised credentials exposed technical data

The incident occurred in mid-July 2026 and involved login credentials for a data exchange platform used by one of Stadler’s suppliers. According to the company, the compromised credentials allowed cybercriminals to obtain access to specific technical information.

Stadler⁠ said the attackers did not penetrate its own IT infrastructure. The group’s internal systems remained intact and continued operating normally after the breach.

The manufacturer also stated that the accessed information was not relevant to railway safety. No sensitive personal data was stolen, and Stadler said none of its rail vehicles operating worldwide had been affected.

The distinction limits the reported operational impact of the incident: the breach involved supplier-related information held on an exchange platform rather than Stadler’s production, corporate or onboard train systems.

Don’t miss…New MOU coordinates Palmdale high-speed rail connection

Stadler refuses CHF 10 million ransom demand

The Everest cybercriminal group claimed responsibility and demanded CHF 10 million from Stadler. The train manufacturer said it would not pay the ransom under any circumstances.

Stadler has filed a criminal complaint with the cantonal police in Thurgau, Switzerland, where the company is headquartered. No further details were provided about the affected supplier, the volume of technical information obtained or whether the attackers had published any of the data.

The company’s response leaves several aspects of the investigation undisclosed, but its current position is that the breach created no safety risk for passengers, operators or Stadler-built trains already in service.

News on railway transport, industry, and railway technologies from Railway Supply that you might have missed: