news.mlab.sh
Back to the feed
threat-intel

Swiss train maker Stadler refuses Everest $12 million ransomware demand

High
Summary

Swiss train manufacturer Stadler Rail refused a $12.3 million ransomware demand from the Russian-speaking group Everest after cybercriminals stole technical data from a supplier’s file-sharing platform. The incident did not affect Stadler’s own systems, and production remains operational, despite the stolen data and a previous extortion attempt in 2020.

Swiss train manufacturer Stadler Rail has refused a $12.3 million ransomware demand from the Russian-speaking group Everest following a data breach involving a supplier’s file-sharing platform. According to a company statement released on Tuesday, the breach occurred in mid-July and resulted in the theft of technical documents belonging to a third-party supplier. The company stated that it did not lose any of its own data and that no personal information was compromised, and that the incident has no impact on trains operating worldwide.

Stadler has filed a criminal complaint and will not negotiate with the hackers. This is the second known extortion attempt against Stadler in recent years, with a previous incident in 2020 where attackers infiltrated the company’s systems, stole internal data, and demanded roughly $6 million in bitcoin. After Stadler refused to pay, the attackers published samples of the stolen files, including financial and administrative documents.

Everest is a Russian-speaking ransomware and extortion group active since at least 2020, and has targeted organizations in critical infrastructure sectors, including energy, transportation, and telecommunications. Last year, the group claimed responsibility for a cyberattack involving an external file transfer system used by Sweden’s state-owned electricity grid operator, Svenska kraftnät, although the incident did not disrupt power supplies. More recently, Everest claimed responsibility for a breach involving a contractor for Japanese automaker Nissan, where attackers compromised systems operated by the third-party vendor but found no evidence that its own customer data had been accessed.

Read the full article at The Record