Stadler has released an official statement regarding a cyberattack that befell a supplier mid-July 2026, claiming that whilst cybercriminals illegally gained access to a data exchange platform, Stadler did not lose any data as a result.
The company has stated that access to specific technical data was gained via compromised login credentials for a data exchange platform, which subsequently fell into the hands of cybercriminals.

Stadler has confirmed that its own IT systems were not compromised and remained intact, with affected data confirmed to have been technical in nature, and not security-relevant. No personal data was stolen, and the company’s rail vehicles operating worldwide are in no way affected by the data theft.
In a letter claiming responsibility; cybercriminal Everest Group is demanding a ransom of 10 million CHF, with Stadler since confirming it has no intention of paying under any circumstances – having now subsequently filed a criminal complaint with the Thurgau cantonal police.
Stadler has declined any further comment.























