Analyst assessment
DysruptionHub assesses with high confidence that Evergreen Printing Company experienced a malicious cyber incident in December 2025. Our reporting drew on the affected customer newspaper The Retrospect, which identified ransomware and said Evergreen’s systems were locked up around Dec. 19. A later Kaspersky ICS CERT review also listed the printer’s December disruption as ransomware. Kaspersky’s table names Qilin, but the reviewed material does not include a verifiable actor post or independent proof of that attribution.
Operational significance
The disruption affected press operations, subscriber mail lists and company communications. The Retrospect warned that subscribers might see delivery errors while staff rebuilt mailing lists. The incident therefore affected both Evergreen’s production and at least one downstream newspaper customer; the record does not establish effects at every customer.
Current status
An Evergreen representative told The Retrospect that the company activated its incident-response plan and engaged outside experts. No reviewed source establishes an exact restoration date or a final account of the affected systems. Because the last documented operational impact was in December 2025, this retrospective record is presumed resolved, without claiming a confirmed all-clear.
Confidence and uncertainty
The local customer’s first-hand account and Evergreen’s response statement support high confidence in a cyber incident and material disruption. Ransomware is supported by the customer report and later industry review, but public details of encryption, a ransom demand and any payment are limited. Evergreen said it was not aware of evidence confirming that personal data had been accessed or removed; that preliminary statement is not a final forensic finding.
Analytic gaps
The initial access method, malware variant, actor identity, full customer impact, final restoration date and data-exposure outcome remain unresolved.