Swiss rail manufacturer Stadler Rail rejected a ransom demand from the Everest gang following a breach of a supplier data exchange platform. The attackers demanded approximately $12.3 million for stolen data.
Stadler Rail, a major Swiss manufacturer of rail vehicles, confirmed it was targeted by the Everest ransomware group after a cyberattack compromised a shared data platform used with one of its suppliers.
The attackers demanded $12.3 million in exchange for not releasing the stolen information. Stadler declined to pay, stating it would not negotiate with the threat actors.
The breach affected a data exchange platform—a common IT infrastructure used by companies to share files with business partners. The shared nature of such platforms means the attack potentially exposed data from multiple organizations connected to Stadler's supplier network.
Everest is a known ransomware-as-a-service (RaaS) operation that has targeted organizations across multiple sectors. The group typically exfiltrates data before deploying encryption, then demands payment under threat of public data release.
Stadler Rail's refusal to pay aligns with guidance from law enforcement and cybersecurity authorities, who discourage ransom payments as they fund criminal operations and encourage further attacks. The company stated it was working with cybersecurity experts and relevant authorities to investigate the incident.
No details were provided regarding the extent of data accessed or whether any customer or employee information was compromised. The company did not disclose how long the breach went undetected or when it was discovered.
Railway and transportation infrastructure remains a critical sector facing increased cybersecurity threats. Attacks on manufacturers in this space can have significant operational and supply chain implications across Europe.
Stadler Rail produces rail vehicles for operators across Switzerland and internationally. The company has not announced service disruptions related to the incident, suggesting operational systems were not affected by the breach.
QBittorrent, the popular open-source torrent client, has been found capable of breaking out of sandbox environments to execute unauthorized operations. Security researchers identified the vulnerability, raising concerns about the application's access to system resources.
Threat actors are deploying invisible Unicode characters in phishing campaigns to evade email security systems. The ASCII smuggling technique allows attackers to conceal malicious content from detection tools.
A Unicode block invisible to human readers has transitioned from an academic curiosity used to test AI systems into an active tool for spammers. The technique exploits characters that machines process but humans cannot see.
A study found that 86% of licensed British gambling websites violate GDPR privacy requirements, using deceptive cookie banners to track users before obtaining consent.