Skip to content

Evergreen Printing ransomware disruption

Summary

Evergreen Printing Company logo

A ransomware attack at Evergreen Printing Company in Bellmawr, New Jersey, disrupted newspaper printing and subscriber fulfillment in December 2025. A customer publication reported problems with press operations, mailing lists and company communications as Evergreen investigated and restored systems.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted location

Organization types

Incident characteristics

Assessments

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Manufacturing or production disruption

    Manufacturing, production, assembly, processing, or industrial operations were reduced, stopped, or impaired.

  • Supply chain disruption

    Procurement, inventory, warehousing, shipping, delivery, vendor, or other supply-chain processes were materially affected.

  • Downstream organization impact

    The incident caused operational effects at customers, affiliates, subsidiaries, partners, tenants, or other dependent organizations.

Extortion indicators

  • Unknown extortion indicators

    The incident may involve extortion, but available evidence does not establish which extortion indicators were present.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Evergreen Printing Company experienced a malicious cyber incident in December 2025. Our reporting drew on the affected customer newspaper The Retrospect, which identified ransomware and said Evergreen’s systems were locked up around Dec. 19. A later Kaspersky ICS CERT review also listed the printer’s December disruption as ransomware. Kaspersky’s table names Qilin, but the reviewed material does not include a verifiable actor post or independent proof of that attribution.

Operational significance

The disruption affected press operations, subscriber mail lists and company communications. The Retrospect warned that subscribers might see delivery errors while staff rebuilt mailing lists. The incident therefore affected both Evergreen’s production and at least one downstream newspaper customer; the record does not establish effects at every customer.

Current status

An Evergreen representative told The Retrospect that the company activated its incident-response plan and engaged outside experts. No reviewed source establishes an exact restoration date or a final account of the affected systems. Because the last documented operational impact was in December 2025, this retrospective record is presumed resolved, without claiming a confirmed all-clear.

Confidence and uncertainty

The local customer’s first-hand account and Evergreen’s response statement support high confidence in a cyber incident and material disruption. Ransomware is supported by the customer report and later industry review, but public details of encryption, a ransom demand and any payment are limited. Evergreen said it was not aware of evidence confirming that personal data had been accessed or removed; that preliminary statement is not a final forensic finding.

Analytic gaps

The initial access method, malware variant, actor identity, full customer impact, final restoration date and data-exposure outcome remain unresolved.

Threat actor and claim

Listed as: Evergreen PrintingSource: ransomware.liveDiscovered:

Claim details

Qilin’s victim listing named Evergreen Printing, and Kaspersky ICS CERT later associated Qilin with the December 2025 printer disruption. The indexed listing uses egpp.biz while the Bellmawr, New Jersey printer identifies egpp.com as its website. The group claim and its identity match have not been independently confirmed; this record does not establish Qilin’s role, data theft or a link to the operational outage.

Organizations involved

Impacted location

Sources

Ransomware at New Jersey printer disrupts newspaper mailings

We reported that The Retrospect identified a ransomware attack at Evergreen Printing around Dec. 19, 2025, and described disrupted printing, subscriber fulfillment and company communications. Evergreen said it activated incident response and was investigating.

A brief overview of the main incidents in industrial cybersecurity, Q4 2025

The Q4 2025 industrial cybersecurity review lists Evergreen Printing as a U.S. printer affected by denial of IT systems and services and ransomware in December 2025, and names Qilin without supplying a verifiable actor post in the reviewed table.

See something that needs correction?

Signed-in members can report an error, update, or missing source.