← All articles

consultant

Stadler Rail: $12.3M Ransom Demand — Practical IAM to Meet NIS 2 and GDPR

On July 22, 2026, Stadler Rail rejected a $12.3M ransom after data was exfiltrated via a supplier file-sharing platform. Here is measurable IAM that limits third-party access and aligns with NIS 2 and GDPR.

Excerpt — On July 22, 2026, Stadler Rail confirmed a $12.3M extortion attempt by “Everest” via a supplier’s file-sharing platform. Below is the IAM governance that prevents a third-party access from opening the entire shop.

What happened

On July 22, 2026, Swiss rail manufacturer Stadler Rail reported receiving a ransom demand of about $12.3M (10M CHF) from the “Everest” group, following the theft of technical documents from a file-sharing platform used with a supplier. The company refused to pay and filed a complaint. Early indications align: the attack did not encrypt Stadler’s internal systems but abused a supplier access to a third-party service to exfiltrate data, showcasing a typical supply chain risk and insufficient access control on the provider side and inter-company sharing. Sources: The Record, BleepingComputer.

The applicable legal framework

In short: if a third party or a sharing platform becomes the entry point, missing IAM (identity governance, authentication, authorization, periodic review) creates exposure to NIS 2 and GDPR non-compliance — with real impacts.

The technical solution: governed and measurable IAM

Objective: reduce “supplier access” risk and file theft/exfiltration via verifiable identity, authentication, and authorization controls integrated into the subcontracting chain.

  • Frameworks: ISO/IEC 27001 Annex A (A.5.15 access control, A.5.16 secret management, A.8.3 application information security), NIST CSF 2.0 (PR.AA, PR.AC), and CIS Controls v8 (CIS 6, CIS 5).
  • Authentication controls:
    • Phishing-resistant MFA (FIDO2/WebAuthn) for all B2B and supplier access (guest, partner accounts), with attested enrollment of security keys.
    • Conditional access policies (geolocation, device posture, risk score) and just-in-time access for sensitive operations (share link creation, bulk exports, APIs).
  • Authorization and least privilege:
    • Business roles and segmented application scopes; separation of customer/supplier environments; time-bound access (expirable links and accounts).
    • Quarterly access reviews (attestations), automatic deprovisioning via SCIM/HRIS, and governed access certifications.
  • Monitoring and exfiltration prevention:
    • Detailed logging of sharing actions, mass downloads, and API access; SIEM rules for “impossible travel,” “download spikes,” and “token reuse.”
    • DLP at critical points (browser/agent, SaaS connectors) to block bulk downloads, unauthorized public sharing, and uploads to unapproved repositories.
  • Hardening of sharing platforms:
    • Disable public links by default, require named links protected by MFA, enable watermarking and view-only for sensitive drawings.
    • Bring Your Own Key and Customer-managed keys where offered by the SaaS; immutable audit log for evidence.

These measures constitute, “for NIS 2 purposes,” technical and organizational measures covering access, suppliers, and detection; “for GDPR purposes,” they demonstrate Article 25 by design and by default for any file containing personal data.

How Luxgap delivers this

  • Our ISO 27001 governance: scoping IAM policies (roles, attestation cycles, JIT), mapping B2B flows, and embedding NIS 2 Art. 21(2) requirements (supply chain, MFA, access management). We co-author procedures and audit evidence (screenshots, signed exports, reviews).
  • Our 24/7 managed SOC: ingest IdP/SaaS logs, correlate “exfiltration” and “access anomalies,” provide ready-to-use alerts (download spikes, unusual external sharing, unrecognized FIDO key), and a containment runbook (session revocation, key rotation, public-link kill switch).
  • Our fractional CISO consultants and DPO: align with GDPR Art. 25 (restrictive defaults, access minimization), maintain the NIS 2 register of measures, and set supplier-access clauses (MFA, logs, reviews, notification).

EU or Luxembourg case study

A European industrial company (NIS 2 “important” entity, equipment-supplier chain) used a SaaS file-sharing platform with suppliers for drawings and BOMs. In 6 weeks:

  • Rolled out a federated IdP for guest accounts, mandatory FIDO2 MFA, and country-based conditional access.
  • Implemented a role-based authorization model and time-bound links (auto-expire at 14 days), view-only and watermark on sensitive docs.
  • Connected SIEM/DLP to detect bulk downloads and block uploads to unapproved repositories.

Outcome: public sharing disabled, 78% reduction of permanent supplier access, real-time alerts on mass extraction, exportable evidence for NIS 2 audits and GDPR Art. 25 documentation.

Practical first steps

  1. Map your sharing platforms within 7 days (M365/SharePoint, Box, Google Drive, managed SFTP, PLM portals) and identify active supplier accounts and public links.
  2. Block anonymous links by default and require named links with MFA. Enable automatic share expiration.
  3. Enable phishing-resistant MFA (FIDO2/WebAuthn) for partners and admins. Prohibit SMS OTP for sensitive access.
  4. Automate supplier on/offboarding (SCIM or workflows) and launch a targeted “third-party” access review (30 minutes per app owner).
  5. Feed your IdP/SaaS logs into a SIEM and add 3 simple rules: “mass downloads,” “sudden external sharing,” “login from new country” — with session-revocation playbooks.

Official sources

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →