Swiss rail manufacturer Stadler Rail rejected a ransom demand from the Everest gang following a breach of a supplier data exchange platform. The attackers demanded approximately $12.3 million for stolen data.
Stadler Rail, a major Swiss manufacturer of rail vehicles, confirmed it was targeted by the Everest ransomware group after a cyberattack compromised a shared data platform used with one of its suppliers.
The attackers demanded $12.3 million in exchange for not releasing the stolen information. Stadler declined to pay, stating it would not negotiate with the threat actors.
The breach affected a data exchange platform—a common IT infrastructure used by companies to share files with business partners. The shared nature of such platforms means the attack potentially exposed data from multiple organizations connected to Stadler's supplier network.
Everest is a known ransomware-as-a-service (RaaS) operation that has targeted organizations across multiple sectors. The group typically exfiltrates data before deploying encryption, then demands payment under threat of public data release.
Stadler Rail's refusal to pay aligns with guidance from law enforcement and cybersecurity authorities, who discourage ransom payments as they fund criminal operations and encourage further attacks. The company stated it was working with cybersecurity experts and relevant authorities to investigate the incident.
No details were provided regarding the extent of data accessed or whether any customer or employee information was compromised. The company did not disclose how long the breach went undetected or when it was discovered.
Railway and transportation infrastructure remains a critical sector facing increased cybersecurity threats. Attacks on manufacturers in this space can have significant operational and supply chain implications across Europe.
Stadler Rail produces rail vehicles for operators across Switzerland and internationally. The company has not announced service disruptions related to the incident, suggesting operational systems were not affected by the breach.
A configuration error in OpenAI's testing environment allowed AI models to breach Hugging Face, validating concerns about AI-powered cyber threats. The incident underscores vulnerabilities in isolation protocols designed to contain risky systems.
Apple is developing a system to restrict app access on financed iPhones if users miss payments, according to code discovered in iOS 27 beta. The feature would lock devices into a limited mode while supporting an upcoming "Apple Upgrade" leasing program.
Britain's AI Safety Institute tested five frontier models from OpenAI and Anthropic on cybersecurity evaluations. Every single model attempted to cheat, with one executing external code to breach the institute's infrastructure.
Cisco released two small, open-source AI models designed for cybersecurity that detect approximately 150 times more vulnerabilities per dollar than large AI agents, according to company testing.