Swiss Train Co Kicks Ransomware Gang to the Curb

Stadler Rail’s Daring Stance Against Cybercriminals

Swiss rail producer Stadler Rail encountered a CHF 10 million ($12.3 million) ransom request from the Everest ransomware group following the breach of one of Stadler’s suppliers. Did they back down? Absolutely not, Stadler brushed them off. According to their statement, the hackers only succeeded in acquiring technical details from a supplier, with no ‘security-sensitive data’ compromised. In short: “no significant personal data was taken,” and the incident had no influence on their trains, trams, or worldwide manufacturing operations.

Data Exchange Portal: The Hacker’s Access Point

The wrongdoers accessed the technical information through a ‘data exchange portal’ used between Stadler and their enigmatic supplier, utilizing stolen login details to gain entry. But Stadler’s own IT infrastructure? Completely unscathed, they remained robust and intact. As it stands, Stadler is not featured on Everest’s data leak site (DLS), and the stolen technical information has not surfaced.

Disrupting the Usual Cybercrime Playbook

Typically, these cyber miscreants adhere to a playbook: they steal or encrypt data, demand a ransom, and threaten to reveal information if payment isn’t made. Miss the deadline like Stadler did, and companies frequently find themselves listed on the extortionist’s DLS. At that point, a second timer activates, increasing the pressure to pay or confront a data breach. If you pay, you’re removed from the DLS. If not, your data is left exposed. But Stadler’s resistance and absence from Everest’s DLS is quite intriguing, isn’t it?

Everest: A Cybercrime Syndicate

The Everest team, a collection of Russian-speaking cybercriminals, has been wreaking havoc since around December 2020. They’ve targeted prominent companies like Under Armour, Mailchimp, AT&T, and Collins Aerospace, to name a few. Utilizing both no-encryption and double-extortion methods, they have also explored initial access brokering and recruiting corporate insiders. Quite a crafty bunch, aren’t they?

Conclusion: Stadler’s Guts, Everest’s Lack Thereof

So there you have it, everyone: Stadler Rail has stood up to the Everest group and emerged victorious. No data breaches, no ransom surrendered, just a resounding ‘go away’ to the cyber misfits. While Everest may employ elaborate tactics, it’s evident Stadler is operating in an entirely different arena – and succeeding.

Discover more tech stories over at GadgetLad!