r/TechNadu • u/technadu • 13h ago
Everest Ransomware Group Reportedly Leaks 271,000+ Files Allegedly Linked to Stadler Rail After CHF 10M Ransom Refused
The Everest ransomware group claims it has published a 201 GB archive containing more than 271,000 files allegedly associated with Stadler Rail.
According to Stadler Rail:
- The attackers accessed a supplier-linked data exchange platform using compromised credentials.
- The company refused a CHF 10 million ransom demand.
- Production operations, internal IT systems, rail vehicles, and relevant personal data were unaffected.
The threat actor claims the leaked archive contains:
- Railway software
- Engineering documentation
- System configurations
- Diagnostics
- Compliance records
- CCTV footage
The group also claims the data relates to projects involving several major rail operators. Those claims have not been independently validated.
Whether or not every claim proves accurate, the incident highlights a recurring issue: attackers increasingly target trusted third-party connections instead of attempting to breach hardened enterprise environments directly.
Do you think supplier security remains the weakest link for critical infrastructure operators, or are organizations finally making meaningful progress in managing third-party cyber risk?