Stadler has released an official statement regarding a cyberattack that befell a supplier mid-July 2026, claiming that whilst cybercriminals illegally gained access to a data exchange platform, Stadler did not lose any data as a result.

The company has stated that access to specific technical data was gained via compromised login credentials for a data exchange platform, which subsequently fell into the hands of cybercriminals.

Stadler's facility in Salt Lake City
Stadler’s facility in Salt Lake City

Stadler has confirmed that its own IT systems were not compromised and remained intact, with affected data confirmed to have been technical in nature, and not security-relevant. No personal data was stolen, and the company’s rail vehicles operating worldwide are in no way affected by the data theft.

In a letter claiming responsibility; cybercriminal Everest Group is demanding a ransom of 10 million CHF, with Stadler since confirming it has no intention of paying under any circumstances – having now subsequently filed a criminal complaint with the Thurgau cantonal police.

Stadler has declined any further comment.

    Tags

    Get in touch

    Please fill in the contact form opposite. A member of the team will be in touch shortly.








      Advertise with UsGeneral EnquiryEditorial Request

      We'd love to send you the latest news and information from the world of Railway-News. Please tick the box if you agree to receive them.

      For your peace of mind here is a link to our Privacy Policy.

      By submitting this form, you consent to allow Railway-News to store and process this information.