Stadler Rail refuses to pay 10 million franc ransom after data theft
Translated from French, summarized and contextualized by DistantNews.
At a glance
- Swiss rail equipment manufacturer Stadler Rail reported a cyberattack where a supplier's data was stolen.
- Hackers demanded a 10 million franc ransom, but Stadler refused to pay and filed a complaint.
- The company stated its IT systems were not compromised and production continues normally, with no data loss or security risks.
Stadler Rail, a Swiss manufacturer of rail equipment, has fallen victim to a cyberattack that resulted in the theft of data belonging to one of its suppliers. Cybercriminals, identified as the Everest group, demanded a ransom of 10 million Swiss francs for the stolen information.
Despite the demand, Stadler has firmly refused to pay the ransom. The company announced its decision and confirmed it has filed a complaint with the authorities. Stadler emphasized that its own IT systems were not compromised by the attack and that production operations are proceeding as usual.
The stolen data was accessed through compromised login credentials for an exchange platform, which then fell into the hands of the cybercriminals. Stadler assured that no data was lost as a result of the incident and that the compromised information poses no security risks. Crucially, no sensitive personal data was exfiltrated, according to the company's statement.
Stadler will not pay the ransom demanded by the cybercriminal group Everest and has filed a complaint.
Originally published by Le Temps in French. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.