Stadler rejects Everest's $12.3M ransom after a supplier data-exchange platform was breached via compromised credentials; technical data stolen. A giant can refuse. If you share files with suppliers, that portal is in scope—MFA and access reviews, plant floor or small shop.Cyber Resilience desk
What this means for you — CISO:Review supplier file-exchange platforms and the credentials your partners use on them; confirm technical data shared externally is inventoried and covered in your extortion and third-party incident playbooks.
What this means for you — Lean IT orgs:If you share files with a supplier on a common portal, turn on MFA for that account and know exactly what sits there — a partner breach can expose your data without touching your own systems.
What this means for you — MSP:Audit client use of shared supplier file-exchange platforms and enforce MFA on those logins; prioritize manufacturers and industrial clients who push technical drawings or specs to external portals.
What this means for you — Researcher:Everest used compromised credentials on a supplier data-exchange platform and demanded ~$12.3M after taking technical data; watch for leak-site posting and any TTP notes on how the platform was reached.