Evergen Data Breach Exposes Sensitive Corporate and Personal Data

Published: 6 September 2026
Healthcare data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: September 2026

Evergen, a biomaterials manufacturer serving regenerative medicine partners, suffered a ransomware attack claimed by the Chaos threat actor group. Personal and corporate data may have been accessed, though the exact number of affected individuals has not been publicly disclosed. Anyone connected to Evergen through employment or partnership should monitor credit reports and watch for official notification letters.

CompanyEvergen
IndustryHealthcare
Data Types ExposedFull Names, Contact Information, Employment Records, Internal Business and Partner Documents, Financial or Payroll Information, Social Security Numbers
People AffectedNot Publicly Disclosed
Attack MethodRansomware
Regulators NotifiedNot Publicly Disclosed

What Happened in the Evergen Data Breach?

Evergen, a company that develops and manufactures biomaterial products for regenerative medicine partners, has confirmed it was targeted in a ransomware attack. A threat actor group known as Chaos has claimed responsibility for accessing the company’s network. This incident places Evergen among a growing list of healthcare-sector companies hit by ransomware operators in recent months.

Details about the exact timeline remain limited. However, the breach discovery date has not been publicly disclosed. What is known is that Evergen issued notification about the incident in September 2026. Because Evergen works closely with OEM partners on customized biomaterial solutions, the attack may have touched systems containing both corporate and personal data.

As a result of the attack, Evergen likely launched an internal investigation to determine the scope of the intrusion. Companies facing ransomware incidents typically bring in forensic specialists to assess which systems were accessed and what data may have left the network. In addition, affected organizations often work to contain the threat and restore normal operations while the investigation continues.

Ransomware groups like Chaos frequently combine file encryption with data theft, a tactic known as double extortion. This means that even if Evergen restored its systems, the attackers may still hold copies of stolen files. Consequently, the risk to affected individuals does not disappear once systems are back online.

Who was affected?

Evergen has not publicly disclosed the exact number of individuals affected by this breach. Therefore, the full scope remains unclear at this time. However, given the nature of the company’s work in biomaterial manufacturing, those affected could include employees, contractors, and possibly individuals connected to OEM partner organizations.

Because Evergen operates as a contract development and manufacturing organization, its data systems may hold information tied to business partners as well as internal staff. This means the affected population could span multiple organizations rather than a single group of consumers. In addition, healthcare and biotech companies often retain sensitive workforce records, which could place current and former employees at risk.

At this stage, it is not clear whether patients, research subjects, or minors are involved in this breach. Until Evergen releases further details, affected individuals should assume their information could be included if they have any relationship with the company. This includes employment, vendor, or partnership connections.

What Information Was Potentially Exposed?

The exact categories of data accessed during this attack have not been fully detailed in public reporting. However, ransomware attacks on companies like Evergen commonly involve exposure of both personal and corporate information. Based on the nature of the business and typical breach patterns in this sector, the following data types may be at risk.

  • Full names
  • Contact information such as addresses, phone numbers, or emails
  • Employment records
  • Internal business and partner documents
  • Financial or payroll information
  • Potentially Social Security numbers, if held for payroll or HR purposes

If personal identifiers were indeed included in the stolen data, affected individuals could face a heightened risk of identity theft. Criminals often use stolen names, contact details, and financial information to open fraudulent accounts. In addition, this type of data can be used for targeted phishing attempts designed to trick victims into revealing even more sensitive information.

Furthermore, if payroll or Social Security information was exposed, the risk extends beyond simple fraud. Attackers could attempt tax fraud, apply for loans, or create synthetic identities using stolen details. Because ransomware groups often sell stolen data on dark web marketplaces, the exposure window can last for years after the initial attack.

What is the company doing?

Evergen has acknowledged the security incident and is presumably working to secure its systems following the attack. In response to threats like this, companies typically isolate affected systems and bring in outside cybersecurity experts. This helps confirm the scope of unauthorized access and prevent further compromise.

Moving forward, Evergen will likely notify any individuals whose information was confirmed to be involved. Companies facing similar incidents often offer credit monitoring or identity protection services to affected individuals as a precaution. Because full details of Evergen’s remediation plan have not been publicly released, affected individuals should watch for direct notification letters in the coming weeks.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Anyone who may have been affected by this breach should check their credit reports regularly. This allows you to catch new accounts or inquiries you did not authorize. You can request free credit reports from all three major bureaus at annualcreditreport.com.

In addition, reviewing your reports every few months over the next year is a smart precaution. Because stolen data can be used long after a breach occurs, ongoing vigilance matters more than a one-time check. If you spot unfamiliar activity, report it to the credit bureau immediately.

Consider a Fraud Alert or Credit Freeze

If Social Security numbers or financial information were part of this breach, placing a fraud alert on your credit file is a strong first step. A fraud alert requires lenders to verify your identity before approving new credit. This can stop criminals from opening accounts in your name.

For stronger protection, consider a full credit freeze instead. A freeze blocks access to your credit file entirely until you lift it. Although it requires a bit more effort to manage, it offers the highest level of protection against new account fraud.

Watch for Phishing Attempts

Because stolen contact information can be used for scams, be cautious of unexpected emails, texts, or calls. Attackers often pose as trusted companies to trick victims into clicking malicious links. Therefore, never click links or share personal details from unsolicited messages.

Instead, verify any suspicious communication by contacting the company directly through a known phone number or website. This simple habit can prevent you from falling victim to a secondary attack. Phishing attempts often increase in the months following a major data breach.

Consult a Data Breach Attorney

If you believe your information was exposed in this incident, speaking with a data breach attorney can help clarify your options. Many attorneys offer free consultations to review your situation. This means there is little risk in simply asking questions about your rights.

Depending on the facts that emerge about this breach, affected individuals may have grounds to pursue compensation. An attorney can help determine whether you qualify for a class action or individual claim. Because deadlines for filing claims can be strict, seeking advice sooner rather than later is generally wise.



Related Data Breaches

Browse all recent data breaches →