Ransomware victim disclosure
← All victimsevergenbio.com
Claimed by Chaos · listed 4 hours ago
Status timeline
- ListedSep 6, 2026
- Data leakeddate unknown
At a glance
- Group
- Chaos
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Sep 6, 2026
About the victim
AI dossier — public-source company profileEvergen is a Contract Development and Manufacturing Organization (CDMO) specializing in customized biomaterial solutions for regenerative medicine, founded in 1998. The company partners with OEM manufacturers to design, develop, and manufacture allograft and xenograft biomaterials used in plastic/reconstructive surgery, orthopedics, spine, and cardiac applications. They report delivering over 20 million implants and supporting 200+ market authorizations globally.
- Industry
- Contract Development & Manufacturing (CDMO) – Regenerative Medicine & Biomaterials
- Founded
- 1998
Attack summary
Severity: low — Post contains only announcement/listing with no published proof files, no specific data types disclosed, no operational impact stated, and no evidence of data exfiltration beyond the claim itself.The Chaos group claims to have attacked Evergen but provides no detail in the truncated leak post about what data was exfiltrated, encrypted, or the scope of the breach. No specific data categories or proof files are mentioned.
What the group claims
Evergen is a leading Contract Development and Manufacturing Organization (CDMO) specializing in biomaterial solutions for regenerative medicine. We work closely with OEM partners to deliver customized biomaterial solutions that meet specific clinical needs
Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

