Everest Hackers Leak 270,000+ Files Reportedly from Stadler Rail Breach After Swiss Firm Refuses to Pay, Including CCTV Footage, Configurations

Published
Written by:
Lore Apostol
Lore Apostol
Cybersecurity Writer
Key Takeaways
  • Attack claimed: The Everest hacking group leaked a 201 GB FTP archive containing more than 271,000 files tied to Stadler Rail systems.
  • Ransom demand: Everest demanded CHF 10 million (about $12.3 million) after breaching a supplier-linked data exchange platform.
  • Firm response: Stadler Rail refused to pay and confirmed production, internal IT, rail vehicles, and relevant personal data were unaffected.

The Everest ransomware group leaked data allegedly belonging to Swiss rolling stock manufacturer Stadler Rail, including railway software, CCTV footage, engineering documentation, configurations, and more. The threat actor claimed responsibility for a Stadler cyberattack last week but did not list the company on its dark web portal.

Everest Claims 201 GB Data Leak

According to the threat actor, which was first flagged by threat-intelligence tracker HackManac, the data breach yielded a 201 GB FTP archive holding more than 271,000 files. While Stadler said it did not lose any of its own data, the leaked set allegedly spans technical documents:

Everest ransomware group claimed Stadler Rail | Source: HackManac on X
Everest ransomware group claimed Stadler Rail | Source: HackManac on X

Major Rail Operators Named

Everest claims the compromised data touches projects linked to several high-profile operators, including Deutsche Bahn, Merseytravel, Westbahn, and MTR, alongside other unnamed clients. 

If validated, exposure of engineering documentation and system configurations tied to these operators raises concerns around downstream risk to connected railway infrastructure.

Stadler Refuses to Pay CHF 10 Million Extortion Demand

Last week, Stadler Rail confirmed that the attackers gained access through a supplier-linked data exchange platform’s compromised credentials, then issued an extortion demand of CHF 10 million (approximately $12.3 million) that the company declined to meet. The manufacturer stated that production operations, internal IT systems, rail vehicles, and relevant personal data were unaffected by the incident.

The intrusion vector underscores a recurring theme in threat intelligence: third-party and supplier-facing platforms remain a favored entry point for extortion actors seeking to bypass hardened internal perimeters. The Polymarket crypto hack and iRhythm Holdings are among the latest examples of third-party accees points.

The threat actor claimed an Omnicell data breach this month and a Nissan data breach in early 2026. 

Earlier this month, a Telstra nationwide outage disrupted calls, trains, and payments across Australia. In February, Deutsche Bahn confirmed a DDoS attack that disrupted services.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: