Wire · founder news, decoded · operational-macro
Swiss train maker Stadler refuses Everest $12 million ransomware demand
◆ Published
23 July 2026
◆ Topic
operational-macro
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 23 July 2026 · Fusion42 review
Stadler Rail, a Swiss train manufacturer with $4.9 billion in annual revenue, refused a $12.3 million ransom demand from Russian-speaking ransomware group Everest after attackers compromised a third-party supplier's file-sharing credentials and stole technical documents. The breach did not affect Stadler's own systems or production, and the company has filed a criminal complaint and will not negotiate.
This Wire brief sits within Fusion42's coverage of Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.
◆ The Wire takeaway
Your supply chain is now a ransomware target. Everest just proved it doesn't need to break into you directly—compromising your suppliers' shared credentials works fine, and the attacker gets paid either way.
◆ Related on Wire
- Comment: The BSI must not become the BND's zero-day supplier | heise online11 July 2026
- US charges Russian 'bulletproof' web hosts over cyberattacks that netted $62M from ...15 July 2026
- US Imposes Sanctions on Belarusian Man in Ransomware Case14 July 2026
- US unseals charges, offers $10 million reward for info on Russian hackers | Reuters15 July 2026
- U.S. Hits Ransomware Supply Chain With New Sanctions15 July 2026
- Data breach reportedly targets India's Kudankulam nuclear power plant16 July 2026
◆ Topics
Cybersecurity · ransomware · supply-chain-security · critical-infrastructure · third-party-risk · extortion