Build1 publisher2 min readPublished
A stolen supplier credential put Stadler's name on a CHF 10 million extortion demand
The compromise happened on a data-exchange platform Stadler shared with a supplier, using credentials from the supplier's side. Stadler got the CHF 10 million demand, refused it, and went to the cantonal police.
The Engineer · Build desk

What happened
- In mid-July 2026 the Everest ransomware group used stolen login credentials to reach a data-exchange platform Stadler Rail used with one of its suppliers, and exfiltrated technical data from it.
- Everest demanded CHF 10 million not to publish the files it had taken off that platform.
- Stadler refused outright, filed a criminal complaint with the Thurgau cantonal police, and said its own IT systems, production lines and rail vehicles were never touched.
- The exposed technical information belonged to the supplier, and Stadler's own technical, customer and operational data were not part of what Everest claimed to hold.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- exposure The company whose perimeter held is the company the coverage names, so a partner's credential handling becomes your public incident and your board's problem.
- decision Anyone running a joint exchange platform has to settle in advance which party answers an extortion mail about shared data, because the demand does not arrive at the party that lost the credentials.
- constraint A response plan keyed to the question "were we breached" answers no in this case and still leaves a ransom demand, a police report and the press to handle.
- precedent Planning a no-payment posture now means planning for publication as well, since the archive claim followed the refusal.
The compromise ran through a single credential set. It was tied to the supplier's side of the relationship, and it opened a data-exchange platform that Stadler Rail and that supplier both used, according to the dev.to account of the incident [8][1]. Stadler said its IT systems, production lines and rail vehicles were never touched [3].
What the account does not say is whose identity provider issued that login, which party the platform records as the account owner, or how long the supplier's technical files had been sitting in the shared workspace.
The dev.to write-up breaks the incident into five boundary questions and argues that most incident response models assume they collapse to one [11]. Tally the answers and they do not collapse. Data ownership and credential origin both land on the supplier [7][8]. Receipt of the demand and the public response both land on Stadler [9][10]. The fifth, the location of the compromise, lands on a platform described as sitting outside Stadler's own IT environment [12][15].
The legal exposure here is smaller than the reputational exposure. The only proceeding in the record is the criminal complaint Stadler itself filed with the Thurgau cantonal police [3][16]. The account does not mention any notification duty. No contract clause or supplier claim appears either. Stadler carried the press and the demand, and the write-up describes it making the public "we will not pay" statement [10].
Everest then claimed to have published the material, reportedly an archive of more than 271,000 files [5]. The count is the group's own; the write-up notes it has not been independently verified [6]. At the time Stadler disclosed the extortion, its name was not on Everest's leak site and nothing had been posted [4].
It also ships as an eight-slide carousel PDF [13]. For the model to transfer to your shop, two things have to be true: a shared platform where a partner's credentials can reach data whose loss you would be asked to explain, and a programme the outside world knows by your name and not the partner's. Stadler had both, and the write-up is careful to separate this from the commoner shape where a supplier's compromise becomes a route into your own network [14].
What to watch
- Whether Stadler or the supplier names the data-exchange platform, which would let outsiders check which party the account belonged to.
- Any independent verification, or file-level count, of the archive Everest says it posted.
- A claim by the supplier or a regulatory notification that would move legal exposure onto one of the two parties.