Could Your Business Refuse a Ransom Demand?

Keep up with IT Club
Add IT Club as a preferred source in Google Search.
Stadler Rail's reported refusal to pay a 10 million Swiss franc ransom is a useful example of ransomware resilience. IT Club explains how operational continuity, tested backups, data awareness, supplier oversight and incident planning can reduce an attacker's leverage.
Swiss rail manufacturer Stadler Rail recently faced a ransom demand of 10 million Swiss francs following a cyberattack.
It refused to pay.
The useful question is not whether you would say no
If ransomware hit your business tomorrow, would you actually be in a position to refuse the demand?
Stadler's reported experience shows that refusing a ransom depends heavily on what attackers accessed, whether the business can continue operating, how well it can recover and how prepared it was before the attack happened.
Refusing to pay is not, by itself, a cyber-security strategy. The business needs enough resilience to make that decision without being completely dependent on the attackers' cooperation.
What happened?
In July 2026, Stadler Rail discovered that attackers had accessed a data exchange platform shared with one of its suppliers. The Everest ransomware and extortion group reportedly claimed responsibility.
According to Stadler, technical information was taken, but it was not considered security-relevant. The company said that no personal data was taken, rail vehicle production continued without disruption and its core IT systems were not affected.
The attackers demanded 10 million Swiss francs, reported at the time as approximately US$12.3 million. Stadler refused to pay and filed a criminal complaint with local police.
The incident details are reported using careful wording because attribution, the data involved and the operational impact should not be overstated beyond what Stadler and the reporting confirmed.
Why could Stadler refuse?
This is the important part. Stadler appears to have been dealing with an incident whose operational impact was relatively contained. Production continued, core systems were reportedly unaffected, the stolen information was assessed as not security-relevant and no personal information was reportedly involved.
That puts a business in a much stronger position than one facing all of the following at once:
- Every server encrypted
- Microsoft 365 compromised
- Customer data stolen
- Backups destroyed or inaccessible
- Production stopped
- Staff unable to work
- No tested recovery process
The best time to improve your position is before the attack
A business that can continue operating, understand what information is involved and restore important systems has more choices. A business that is completely paralysed has far fewer.
Ransomware is no longer only about encryption
Traditional ransomware focused heavily on encrypting systems and demanding payment for a decryption key. Modern extortion can involve several pressures at once:
- Data theft
- Threats to publish information
- Encryption
- Double extortion
- Pressure on customers or suppliers
Some attacks effectively say: pay us to recover your systems, and pay us or we will publish your data. Backups remain essential, but they do not solve every ransomware problem.
A backup can restore a file. It cannot make stolen confidential information secret again. Businesses need to ask both questions: can we recover our systems, and what information could an attacker steal?
Could your business keep operating?
Imagine losing access tomorrow to the systems your staff use every day. Work through the consequences rather than assuming that the answer will be obvious during a crisis.
- Microsoft 365
- Your main server
- CRM
- Accounting system
- Shared files
- Line-of-business applications
Could employees continue working? Could customers contact you? Could you invoice and pay suppliers? Could you access customer records? Do you know how long recovery would take, and which services need to be restored first?
A business that can continue operating has options
Business continuity is not just a document. It is the practical ability to keep important work moving while systems are isolated, investigated or restored.
Backups give you choices
Good backups do not prevent ransomware. They can prevent ransomware from becoming catastrophic, but only when the business understands and tests them.
- What is backed up?
- How often is it backed up?
- Where are backups stored?
- Can attackers reach them using normal administrator credentials?
- How long are backups retained?
- When was recovery last tested?
- How long would a full restoration take?
Include Microsoft 365 in this review. Email, SharePoint, OneDrive and Teams may contain a large part of an organisation's operational information. A backup strategy should answer how the business gets running again, not merely whether a backup product has been purchased.
A backup that has never been restored is an assumption, not evidence of recoverability. Test representative files and, where appropriate, a controlled system restore.
Know what data attackers could steal
Stadler's reported ability to assess the information involved is an important lesson. Businesses should know where they keep:
- Customer data
- Employee data
- Contracts
- Financial information
- Confidential documents
- Sensitive email
- Supplier information
- Intellectual property
Ask where each category lives, who can access it, how sensitive it is, how long it is retained and which suppliers hold copies. If an organisation cannot answer those questions, assessing a breach becomes much harder.
Information you no longer hold cannot be stolen from you
Do not retain sensitive information indefinitely simply because storage is cheap. Reducing unnecessary data does not prevent an attack, but it can reduce the scope and difficulty of the resulting investigation.
Supplier platforms still create exposure
The Stadler incident reportedly involved a data exchange platform shared with a supplier. A platform does not have to sit inside your own network to create risk.
Business information increasingly moves through supplier portals, CRM systems, file-sharing services, cloud applications, project platforms, APIs and shared workspaces. Each may hold information that matters to your organisation or to the people whose data you handle.
The recent IT Club article explains why a supplier breach can become your data breach:
Why a supplier breach can become your data breach →
Should you ever pay a ransom?
This article is not telling every business that payment is always or never the correct decision. An organisation facing a live incident may need professional legal, security, insurance and crisis-management advice before making a decision.
Payment does not guarantee that systems will be restored, data will be deleted, stolen information will not be sold, the attackers will not return or another criminal group will not obtain the data. Legal and sanctions issues may apply, insurance conditions may apply and law-enforcement involvement may be appropriate.
Reduce leverage rather than make heroic promises
The objective is not to promise that you will never pay. The objective is to reduce the attacker's leverage so payment is less likely to feel like the only option.
How do you reduce ransomware leverage?
The following controls are ordinary security and resilience practice. Together, they make an attack harder to start, harder to extend and easier to recover from.
1. Protect identities
- Use MFA for Microsoft 365, administrator accounts, remote access and cloud services.
- Use passkeys or phishing-resistant authentication where appropriate.
- Remove dormant accounts and review privileged access.
2. Patch systems
Keep Windows, applications, servers, firewalls, VPNs and remote-access tools supported and updated. Unsupported systems are not automatically compromised, but they are harder to defend and harder to fix when a weakness becomes known.
3. Protect endpoints
Use modern endpoint security capable of detecting suspicious behaviour, and make sure someone knows what the alerts mean and what action to take. This is broader than installing antivirus and hoping it catches everything.
4. Maintain proper backups
Back up critical information, protect backups from production credentials, retain useful recovery points and test restores. Write down realistic recovery times rather than relying on a supplier's generic promise.
5. Reduce unnecessary data
Review old customer records, employee information, attachments, exports and test data. Data that has no continuing business, legal or contractual purpose should not remain available indefinitely.
6. Understand suppliers
Know which third parties store your data, process it or exchange sensitive information with you. Record what they hold, which integrations connect to them, how data can be exported and what happens if the service is unavailable.
7. Have an incident-response plan
- Who gets called?
- Who isolates systems?
- Who contacts your IT or security provider?
- Who contacts the cyber insurer?
- Who makes business decisions?
- Who contacts law enforcement?
- How do communications continue if normal systems are unavailable?
Related Reading
Could your business recover from a serious cyberattack?
If you're not sure whether your backups, security or recovery arrangements would actually work when needed, Ask the IT Club Advisor. One straightforward IT question. Independent guidance without the sales pitch.
The IT Club view
Stadler refusing a multimillion-dollar ransom makes a good headline. But “never pay ransomware” is not the useful lesson.
The useful lesson is to build a business that does not become completely dependent on the attacker's cooperation. That means protecting identities, keeping systems secure, knowing where important data lives, maintaining tested backups, understanding supplier dependencies, planning business continuity and knowing who to call.
Ransomware works by creating leverage
Good cyber resilience is about taking that leverage away.
Sources and further reading
This article is original IT Club commentary and explanation. Brigantia surfaced the Stadler story internally. The incident details and reported attribution should be checked against the latest source updates before being used for formal decisions.
BleepingComputer: Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack →
Plain-English Takeaway
The useful lesson from Stadler Rail is not that every business should promise never to pay. It is that tested recovery, continued operations, known data, understood suppliers and a prepared response can reduce the attacker's leverage and make payment less likely to feel like the only option.
Frequently asked questions
Should a business always refuse to pay a ransomware demand?
There is no universal answer that applies to every incident. Payment does not guarantee that systems will be restored or data will be deleted, and legal, sanctions, insurance and law-enforcement considerations may apply. The practical objective is to reduce the attacker's leverage before an incident so the business has more options.
Do backups solve a ransomware attack?
Backups can help restore systems and data, but they do not make stolen information secret again. They are only useful if the business knows what is covered, protects backups from ordinary production credentials, retains them for long enough and has tested how restoration would work.
Can a supplier platform create ransomware risk for my business?
Yes. Supplier portals, CRM systems, file-sharing services, cloud applications and shared workspaces may hold important information outside your own network. A supplier-linked incident can create operational, confidentiality and reporting questions even when your own core systems continue running.
What should a small business do first to improve ransomware resilience?
Start with identity protection, supported and patched systems, tested backups, a list of important data and suppliers, and a written incident-response plan. Make sure somebody knows who can isolate systems, contact advisers and keep communications running if normal systems are unavailable.
Related Articles
You Can't Fix Every Cybersecurity Risk at Once. So What Comes First?
There will always be more cybersecurity work than time and budget. Here is a practical way to decide what genuinely needs fixing first.
Read articleAI Agents Are Starting to Hack Without Waiting for Humans
Attackers are beginning to use AI agents to investigate systems, change tactics and work in parallel. Here is what that means for ordinary businesses.
Read articleOne SaaS Breach Can Become Hundreds of Data Incidents
A breach at one cloud supplier can create data incidents across hundreds of customers. Here is what the Beacon CRM incident teaches businesses about supplier risk.
Read article