Stadler Rail: $12.3M Ransom Demand — Practical IAM to Meet NIS 2 and GDPR
On July 22, 2026, Stadler Rail rejected a $12.3M ransom after data was exfiltrated via a supplier file-sharing platform. Here is measurable IAM that limits third-party access and aligns with NIS 2 and GDPR.
Excerpt — On July 22, 2026, Stadler Rail confirmed a $12.3M extortion attempt by “Everest” via a supplier’s file-sharing platform. Below is the IAM governance that prevents a third-party access from opening the entire shop.
What happened
On July 22, 2026, Swiss rail manufacturer Stadler Rail reported receiving a ransom demand of about $12.3M (10M CHF) from the “Everest” group, following the theft of technical documents from a file-sharing platform used with a supplier. The company refused to pay and filed a complaint. Early indications align: the attack did not encrypt Stadler’s internal systems but abused a supplier access to a third-party service to exfiltrate data, showcasing a typical supply chain risk and insufficient access control on the provider side and inter-company sharing. Sources: The Record, BleepingComputer.
The applicable legal framework
- NIS 2 — Article 21: mandates cyber risk management measures covering supply chain security, access management, and multifactor authentication “where appropriate.” Essential/important entities (transport, critical industry, IT providers…) must evidence effective controls on third-party access and data exchange with suppliers. See also the NIS 2 Directive and its requirements. References: EUR‑Lex — Directive (EU) 2022/2555, Implementation Guide — Implementing Regulation (EU) 2024/2690.
- GDPR — Article 25 (“data protection by design and by default”): when files may contain personal data (named drawings, accounts, customer/supplier identifiers, etc.), the architecture must embed proportionate access controls by default and audit trails. See the GDPR Article 25 overview. Reference: European Commission — obligations (Art. 25).
In short: if a third party or a sharing platform becomes the entry point, missing IAM (identity governance, authentication, authorization, periodic review) creates exposure to NIS 2 and GDPR non-compliance — with real impacts.
The technical solution: governed and measurable IAM
Objective: reduce “supplier access” risk and file theft/exfiltration via verifiable identity, authentication, and authorization controls integrated into the subcontracting chain.
- Frameworks: ISO/IEC 27001 Annex A (A.5.15 access control, A.5.16 secret management, A.8.3 application information security), NIST CSF 2.0 (PR.AA, PR.AC), and CIS Controls v8 (CIS 6, CIS 5).
- Authentication controls:
- Phishing-resistant MFA (FIDO2/WebAuthn) for all B2B and supplier access (guest, partner accounts), with attested enrollment of security keys.
- Conditional access policies (geolocation, device posture, risk score) and just-in-time access for sensitive operations (share link creation, bulk exports, APIs).
- Authorization and least privilege:
- Business roles and segmented application scopes; separation of customer/supplier environments; time-bound access (expirable links and accounts).
- Quarterly access reviews (attestations), automatic deprovisioning via SCIM/HRIS, and governed access certifications.
- Monitoring and exfiltration prevention:
- Detailed logging of sharing actions, mass downloads, and API access; SIEM rules for “impossible travel,” “download spikes,” and “token reuse.”
- DLP at critical points (browser/agent, SaaS connectors) to block bulk downloads, unauthorized public sharing, and uploads to unapproved repositories.
- Hardening of sharing platforms:
- Disable public links by default, require named links protected by MFA, enable watermarking and view-only for sensitive drawings.
- Bring Your Own Key and Customer-managed keys where offered by the SaaS; immutable audit log for evidence.
These measures constitute, “for NIS 2 purposes,” technical and organizational measures covering access, suppliers, and detection; “for GDPR purposes,” they demonstrate Article 25 by design and by default for any file containing personal data.
How Luxgap delivers this
- Our ISO 27001 governance: scoping IAM policies (roles, attestation cycles, JIT), mapping B2B flows, and embedding NIS 2 Art. 21(2) requirements (supply chain, MFA, access management). We co-author procedures and audit evidence (screenshots, signed exports, reviews).
- Our 24/7 managed SOC: ingest IdP/SaaS logs, correlate “exfiltration” and “access anomalies,” provide ready-to-use alerts (download spikes, unusual external sharing, unrecognized FIDO key), and a containment runbook (session revocation, key rotation, public-link kill switch).
- Our fractional CISO consultants and DPO: align with GDPR Art. 25 (restrictive defaults, access minimization), maintain the NIS 2 register of measures, and set supplier-access clauses (MFA, logs, reviews, notification).
EU or Luxembourg case study
A European industrial company (NIS 2 “important” entity, equipment-supplier chain) used a SaaS file-sharing platform with suppliers for drawings and BOMs. In 6 weeks:
- Rolled out a federated IdP for guest accounts, mandatory FIDO2 MFA, and country-based conditional access.
- Implemented a role-based authorization model and time-bound links (auto-expire at 14 days), view-only and watermark on sensitive docs.
- Connected SIEM/DLP to detect bulk downloads and block uploads to unapproved repositories.
Outcome: public sharing disabled, 78% reduction of permanent supplier access, real-time alerts on mass extraction, exportable evidence for NIS 2 audits and GDPR Art. 25 documentation.
Practical first steps
- Map your sharing platforms within 7 days (M365/SharePoint, Box, Google Drive, managed SFTP, PLM portals) and identify active supplier accounts and public links.
- Block anonymous links by default and require named links with MFA. Enable automatic share expiration.
- Enable phishing-resistant MFA (FIDO2/WebAuthn) for partners and admins. Prohibit SMS OTP for sensitive access.
- Automate supplier on/offboarding (SCIM or workflows) and launch a targeted “third-party” access review (30 minutes per app owner).
- Feed your IdP/SaaS logs into a SIEM and add 3 simple rules: “mass downloads,” “sudden external sharing,” “login from new country” — with session-revocation playbooks.
Official sources
- Incident — The Record: “Stadler refuses Everest $12M ransom demand” (July 22, 2026); BleepingComputer: “Stadler rejects $12.3M ransom demand” (July 22, 2026).
- Regulatory — NIS 2 — Directive (EU) 2022/2555 — Art. 21; Implementing Regulation (EU) 2024/2690 — technical requirements Art. 21(2); GDPR — Art. 25 “Privacy by design” (European Commission).
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →