Two manufacturers on opposite sides of the world were extorted in the same week, and the contrast between them is instructive.

Stadler Rail, the Swiss builder of trains that run across Europe and North America, disclosed a supplier-related breach after attackers obtained credentials for a third-party file-sharing platform and stole technical documents belonging to a supplier. The Everest group demanded $12.3 million. Stadler refused to pay.

Nichirei, one of Japan’s largest food processing and cold-chain logistics companies, was hit by RansomHouse, which claimed the attack after stealing personal data. The operational impact was the story: shipping was disrupted, and roughly 5,000 customers were affected.

Stadler: The Data Was Not Even Theirs

The Stadler case is worth reading carefully because of where the data lived. The compromised platform was a third-party file-sharing service, and the documents taken were a supplier’s technical files — not Stadler’s own engineering repository.

This is the shape modern industrial extortion actually takes. Large manufacturers exchange technical documentation with hundreds of suppliers continuously: drawings, specifications, qualification data, test results. That exchange happens on file-sharing platforms because email cannot carry the file sizes and neither party will grant the other access to internal systems. The platform becomes a permanent, credential-accessible archive of the most sensitive material both companies produce — owned and secured by a third organisation, and typically reviewed once at procurement and never again.

Everest did not need to breach Stadler. It needed one set of credentials to a service Stadler uses.

That Stadler refused a $12.3 million demand is the right call and a fairly easy one on these facts. The stolen material is a supplier’s technical documentation, not customer PII with regulatory exposure, and paying an extortion demand does not retrieve data that has already been copied — it purchases a promise from a criminal enterprise. Groups have repeatedly leaked data after payment or re-extorted the same victim later.

The harder question Stadler now owns is the one it cannot refuse: informing the supplier whose documents were taken, and working out what a competitor or state actor gains from them.

Nichirei: Data Theft Was the Sideshow

Nichirei runs food processing and one of Japan’s largest temperature-controlled logistics networks. RansomHouse claimed personal data theft, but the operational hit — disrupted shipping affecting around 5,000 customers — is what makes this a different category of incident.

Cold-chain logistics does not tolerate downtime the way most sectors do. A halted warehouse management system means product sitting at temperature with a clock running against it, missed delivery windows into retail and food service, and — depending on how long it lasts — spoilage that is unrecoverable rather than merely delayed. The pressure to restore fast is enormous, and every ransomware operator targeting logistics knows it.

RansomHouse occupies a slightly unusual position in the extortion ecosystem. It has historically positioned itself as a data-brokerage operation rather than a conventional encryptor, claiming to monetise stolen data from victims it says had inadequate security — a framing that changes nothing material for the victim but does mean the group has, at times, exfiltrated without encrypting. The shipping disruption at Nichirei suggests either encryption was deployed or the response required taking systems down defensively. Both are common; the distinction matters for recovery planning and not much else.

The Common Thread

Neither of these companies was breached because of a novel exploit. Stadler’s entry point was credentials to somebody else’s platform. Nichirei’s exposure ran through the operational systems that keep physical goods moving.

Manufacturing has spent a decade being told its risk is nation-state IP theft and OT compromise. The actual week-to-week reality is that the sector is being extorted through the ordinary business plumbing — file-sharing services, PLM platforms, warehouse management systems, supplier portals — none of which sit inside the OT security programme and most of which are owned by a third party.

The Cl0p campaign against PTC Windchill and FlexPLM running in the same week is the same lesson from a different angle. So is the concentration risk that made the Craneware breach a 2,000-hospital problem.

Three practical consequences for manufacturers:

Inventory the file-sharing surface. Every platform used to exchange technical data with suppliers is an archive of your most sensitive material under someone else’s control. Enforce MFA on all of them, expire shared links, and delete what does not need to persist.

Extend third-party review past onboarding. Most supplier security assessments happen once, at contract signature, and are never revisited. The credential that compromised Stadler’s supplier data was valid on the day it was used, not on the day the vendor was assessed.

Decide the payment position before you need it. Stadler could refuse $12.3 million cleanly because the calculus was clear. That decision is far harder at 3am with production stopped. Write the policy now.

Sources