Swiss train manufacturer Stadler Rail has declared its refusal to pay a $12.3 million ransom after cybercriminals accessed technical data through a breach in a supplier's file-sharing platform. The attack, which occurred in mid-July, did not compromise Stadler's own systems or affect its production sites. The stolen data was limited to technical documents belonging to a third-party supplier, and no personal information was compromised. Stadler assured that the incident poses no threat to train operations worldwide.

The ransomware group known as Everest has claimed responsibility for this breach, issuing an extortion demand of 10 million Swiss francs. In response, Stadler has filed a criminal complaint and remains adamant about not negotiating with the hackers. "Under no circumstances will Stadler pay a ransom and therefore cannot be extorted," the company stated.

Headquartered in Switzerland, Stadler is a leading rail equipment manufacturer in Europe, providing a range of rail vehicles to global operators. The company employs approximately 18,000 people and generates annual revenue exceeding $4.9 billion.

Stadler did not comment on whether Everest has begun releasing any stolen data, and as of the latest update, the company has not appeared on Everest's dark web site. This incident marks the second extortion attempt against Stadler in recent years. In 2020, the company faced a similar situation when attackers infiltrated its systems, resulting in the leak of financial and administrative documents after a ransom demand went unpaid.

The Everest group, known for targeting critical infrastructure sectors, has been active since at least 2020 and has previously claimed responsibility for attacks on energy and transportation organizations. Experts advise against paying ransoms, as doing so can lead to further attacks. A recent study by Proofpoint found that over half of the organizations that paid ransoms faced additional extortion attempts.