Stadler Rail scoffs at Everst’s $12.3M extortion attempts

https://image.theregister.com/5244900.jpg?imageId=5244900&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

Swiss train maker tells ransomware crooks to get off at the next stop

Stadler refuses $12.3 demand after thieves swipe technical data through supplier platform

Swiss rail manufacturer Stadler Rail says it refused a CHF 10 million ($12.3 million) ransom demand after the Everest ransomware gang compromised one of its suppliers.

Stadler will not pay, and based on its account of events, the company appears to have got off lightly. It stated that "no security-relevant data [was] affected" in the breach, which was limited to "technical information from a supplier."

According to its announcement, "no relevant personal data was stolen," and the incident had no impact on the functioning of its rolling stock (train and tram carriages) or its global production lines.

The attackers accessed the technical data through a "data exchange platform" Stadler used with the unnamed supplier, authenticating with compromised login credentials.

"Stadler's IT systems were not...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE

Read more