Ransomware victim disclosure
← All victimsStadler Rail
Claimed by Everest · listed 3 days ago
Status timeline
- ListedAug 5, 2026
- Data leakeddate unknown
At a glance
- Group
- Everest
- Status
- Data leaked
- Country
- Switzerland
- Sector
- Transportation
- Listed on leak site
- Aug 5, 2026
About the victim
AI dossier — public-source company profileStadler Rail is a Swiss manufacturer of railway vehicles headquartered in Bussnang, founded in 1942. The company designs and produces regional trains, intercity trains, trams, metros, and rack railways, supplying operators across Europe, the Americas, and globally. It is known for product families including FLIRT and KISS trains, and also offers signalling technology and maintenance services.
- Industry
- Rail Vehicle Manufacturing
- Address
- Bussnang, Switzerland
- Founded
- 1942
Attack summary
Severity: low — Only a listing/announcement with no proof files, no explicit data exfiltration claims, no operational impact stated, and no ransom demand. The leak post excerpt contains only generic company background information.The Everest group claims to have conducted an attack on Stadler Rail. No specific details regarding encryption, exfiltration, or data compromise are provided in the available leak post excerpt.
Original description
AI-summarised, not from the leak postStadler Rail is a Swiss manufacturer of railway vehicles headquartered in Bussnang, Switzerland. Founded in 1942, the company designs and produces a wide range of trains including regional and intercity trains, trams, metros, and rack railways. It operates globally, supplying rail operators across Europe, the Americas, and beyond, and is recognized for its FLIRT and KISS train families.
Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

