
Switzerland: Stadler Rail Confirms No Security-Relevant Data Stolen in Cyberattack, Refuses CHF10m Ransom
Stadler Rail said a cyberattack in mid-July 2026 did not compromise its own IT systems, production operations or rail vehicles, after the Everest ransomware group gained access to a data-exchange platform shared with one of Stadler's suppliers using compromised login credentials, according to the company's statement reported by Railway Gazette International and Railway-News.
Stadler said the attackers obtained technical data from the platform that it does not consider security-relevant, and that no personal data was stolen. The Everest group demanded a ransom of CHF10 million (about $12.3 million).
The company said it has "no intention of paying under any circumstances" and that rail vehicles operating worldwide remain unaffected by the data theft. Stadler filed a criminal complaint with the cantonal police in Thurgau, where the company is headquartered.

