Stadler Rail, the Swiss manufacturer behind trains running across Europe and beyond, confirmed in mid-July that the Everest ransomware group had breached a data-exchange platform it shared with one of its suppliers. The attackers got in using compromised login credentials rather than any technical flaw in Stadler’s own systems, and made off with technical documents belonging to the supplier. Everest demanded close to CHF 10 million, roughly $12.3 million, to keep the material private. Stadler refused, stated plainly that it would not pay a ransom under any circumstances, and confirmed that its internal IT infrastructure, production lines, and the trains it has in service worldwide were not touched. After the refusal, Everest published samples of the stolen files.
The breach was never really Stadler’s to prevent
This is the pattern NIS2’s third-party risk provisions were built around. Stadler’s own network security is not what failed here: a shared data-exchange platform, operated for collaboration with a supplier, was the entry point, and stolen credentials were all it took. For a rail manufacturer, that platform sits exactly where a NIS2-covered entity’s attack surface actually lives now, in the connective tissue between itself and its supply chain, not solely inside its own perimeter. Everest is a known quantity in this exact playbook: the group dropped file encryption years ago and runs pure data-theft extortion instead, with a track record that includes carmakers, aerospace suppliers, and a Nordic power grid operator. It targets the supplier relationship because that is where the access control and monitoring tend to be weakest.
Refusing to pay is the easy part. Proving your own systems held is the hard part
Stadler’s response looks confident: no ransom, no personal data exposed, no impact on trains in service. What makes that credible rather than just reassuring is that the company could actually demonstrate its internal systems were unaffected, likely because it could show clean segmentation between its own network and the shared platform that got breached. That is the part most organisations cannot do convincingly under pressure. A public ransom refusal without the forensic evidence to back it up is a gamble; with it, it is a defensible position that regulators, customers, and the market can all verify independently. For any NIS2-covered manufacturer, transport operator, or critical infrastructure supplier, the question this incident raises is not hypothetical: if a platform you share with a supplier or customer were breached tomorrow, could you show the same clean separation, or would you be taking Stadler’s stance without Stadler’s evidence?
If your organisation needs to map its third-party and supply-chain exposure under NIS2, harden the shared platforms and data-exchange integrations that sit outside your own perimeter, or build the segmentation and incident-response evidence trail that lets you refuse a ransom demand with confidence, contact Excello Digital. We help European manufacturers and critical infrastructure operators secure the supplier connections that regulators and attackers are both increasingly focused on.
