GoFirm
Back to Blog
Case Studies·3 min read

Stolen supplier credentials, not a Stadler Rail system, opened the door to a $12.3 million extortion demand

By GoFirm

Stadler Rail, the Swiss manufacturer of locomotives, trams, metro trains and railway signalling systems, disclosed this week that an extortion letter from the Everest gang arrived demanding 10 million Swiss francs, roughly $12.3 million. The incident occurred in mid-July 2026. According to the company's own disclosure, the attackers did not breach Stadler's IT systems or touch its production operations. They reached a data exchange platform shared with one of Stadler's suppliers, and they got in with a valid, compromised login.

Everest abandoned file encryption back in 2020 in favour of straightforward data theft, and this incident followed that pattern exactly. No malware had to run, no vulnerability had to be exploited, and no ransomware payload had to detonate. A working credential was enough to open a session on the shared platform that looked, to any system checking it, identical to a legitimate supplier employee logging in to exchange technical files. Once inside, the attackers pulled the technical data flowing through that platform and followed up with an extortion letter rather than a locked server.

Everest's business model makes this kind of access easy to come by. Beyond running its own extortion campaigns, the group operates as an initial access broker, buying and selling stolen network credentials to other criminals, and it runs a recruitment scheme that pays company insiders directly for access to their employer's systems. The gang has also claimed responsibility for disruptions at Heathrow, Brussels, Berlin, Dublin and Cork airports. Stadler itself was hit by a separate cyber incident in 2020. Rail manufacturing's growing reliance on digital supply chain platforms is only widening the number of doors like this one.

Stadler says the ransom demand covers technical information belonging to its supplier that is not safety-relevant, with no personal data taken and no effect on the trains it operates worldwide. The defences that failed here were not weak by conventional standards. The platform was access-controlled and the login was authenticated normally. The gap was that authentication alone was treated as sufficient proof that the person on the other end had the authority to be there.

A login to a shared supplier platform, and any export of data across it, is an execution event. Before a credential can open a session on a platform like this, or before a batch of technical files can leave it, a confirmation request should go to the named authority responsible for that supplier relationship, sent to their registered device, requiring a biometric confirmation before the session or export is allowed to proceed.

A stolen credential, however valid it looks to the server accepting it, cannot produce that confirmation on the real authority's device over a separate channel. The execution boundary holds regardless of how legitimate the login appears.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence.
Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.

References:


1. Toulas, B. 2026. Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack. BleepingComputer, 22 July 2026.
2. Markovic, S. 2026. Swiss rail manufacturer Stadler refuses to pay $12.3 million ransom after cyberattack. Help Net Security, 23 July 2026.
3. Stadler Rail. 2026. Cybervorfall (cyber incident disclosure). Stadler Rail media release, 22 July 2026.

Share this article