Skip to content
    Switzerland: Stadler Rail Confirms No Security-Relevant Data Stolen in Cyberattack, Refuses CHF10m Ransom
    TechnologySwitzerland

    Switzerland: Stadler Rail Confirms No Security-Relevant Data Stolen in Cyberattack, Refuses CHF10m Ransom

    Stadler Rail said a cyberattack in mid-July 2026 did not compromise its own IT systems, production operations or rail vehicles, after the Everest ransomware group gained access to a data-exchange platform shared with one of Stadler's suppliers using compromised login credentials, according to the company's statement reported by Railway Gazette International and Railway-News.

    Stadler said the attackers obtained technical data from the platform that it does not consider security-relevant, and that no personal data was stolen. The Everest group demanded a ransom of CHF10 million (about $12.3 million).

    The company said it has "no intention of paying under any circumstances" and that rail vehicles operating worldwide remain unaffected by the data theft. Stadler filed a criminal complaint with the cantonal police in Thurgau, where the company is headquartered.

    Related coverage

    Related projects & companies

    Get weekly rail intelligence by email

    Regulatory updates, tender highlights, jobs digest. One email a week, no spam, unsubscribe in one click.