🟠 High  |  Source: The Register — Security


Swiss rail manufacturer Stadler has refused to pay a $12.3 million ransom demand from the Everest ransomware group after attackers exfiltrated sensitive technical data via a third-party supplier platform. The incident highlights the persistent risk of supply chain entry points, where a compromised vendor portal becomes the attack vector into a well-defended primary target. Stadler’s refusal to pay is notable and reflects growing industry consensus that paying ransoms rarely guarantees data deletion or prevents further extortion.

Security Architect’s Take: Audit all third-party supplier portals and integrations for access controls, data minimisation, and monitoring — enforce least-privilege access to technical data repositories and ensure supplier platforms are included in your threat modelling and vendor risk assessments. Consider whether sensitive technical assets such as engineering schematics or IP should ever be accessible through externally-facing supplier portals without additional access controls such as MFA and just-in-time access.

Original advisory: Swiss train maker tells ransomware crooks to get off at the next stop