Evasa Listed by frag Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Evasa was listed by the frag ransomware group on June 11, 2025, after internal files were exfiltrated in a ransomware attack. The number of people affected has not been disclosed; anyone connected to Evasa should check for unusual account activity and change passwords as a precaution.
Ransomware groups continue to pressure organisations by combining system encryption with data theft and public leak-site listings, turning operational disruption into a dual threat of downtime and exposure. In this landscape, even mid-sized specialist firms can find themselves named without warning, leaving employees and partners to assess personal risk from incomplete public details.
On 11 June 2025, the environmental engineering company Evasa was listed by the ransomware group frag, which claimed to have exfiltrated internal files. The number of people affected remains unknown, and independent confirmation of the full scope has not been published. The listing matters because it asserts the theft of sensitive corporate and personal records that, if authentic, could enable identity misuse and financial harm.
Breaking down the breach
Public reporting on 11 June 2025 stated that Evasa had been listed by frag following a ransomware attack in which internal files were claimed to have been exfiltrated. No technical details of the intrusion method, initial access vector, or encryption timeline have been disclosed. The scale of the incident—how many systems were involved or how long the attackers remained inside the network—is likewise unconfirmed. What is known rests on the group’s own leak-site claim rather than a verified forensic report from the organisation or independent investigators.
The listing itself functions as both an assertion of success and a pressure tactic. Beyond the statement that internal files were taken, no further operational chronology or ransom demand figures have entered the public record. Readers should therefore treat the event as an attributed claim pending additional corroboration.
Who is frag?
frag is a ransomware operation that follows the now-common double-extortion model: encrypting systems while simultaneously stealing data and threatening to publish it on a dedicated leak site if payment is not made. Groups of this type typically advertise victims with sample files or descriptive lists of stolen material to increase credibility and urgency. Their public activity is well documented across multiple prior listings of companies in varied sectors; they rarely provide full technical write-ups of their methods, preferring instead to showcase the volume or sensitivity of the data they claim to hold.
In the present case, frag’s listing of Evasa should be read as the group’s unverified claim. No independent confirmation that the files described actually originated from Evasa has been released in the available reporting. Attribution therefore rests on the leak-site post alone.
Evasa and its sector
Evasa is described as an environmental engineering company. Organisations in this field design, assess and manage projects related to environmental compliance, remediation, infrastructure and resource management. They routinely handle internal financial records, employee personnel files, project documentation and, depending on jurisdiction, identity documents required for contracts, travel or regulatory filings.
A breach at such a firm is consequential because the data typically held can include both commercial information that competitors or fraudsters might exploit and personal identifiers belonging to staff. Even when client or project data is not explicitly named, the presence of employee identity documents raises direct risks for the individuals whose records were stored. Public detail about Evasa’s precise size, locations or client base is limited, so the broader sector context supplies the most reliable frame for understanding potential impact.
What was likely exposed
The facts name “internal files exfiltrated in a ransomware attack.” frag’s listing further claims the following specific categories:
- Financial statements of the company
- Employee passports and other personal documents
- DNI scans
These items are presented solely as the group’s assertions. No independent inventory or sample verification has been published, and the total volume of data remains undisclosed. Organisations of Evasa’s type commonly retain payroll records, tax identifiers, scanned identity documents for HR and compliance purposes, and internal accounting files. Whether any of those additional categories were also taken is unconfirmed. Readers should therefore regard the exact contents as claimed rather than proven.
The real-world impact
For individuals whose passports, DNI scans or other personal documents appear in the claimed set, the practical risks include identity theft, fraudulent account openings, and social-engineering attempts that reference real personal details. Financial statements, if authentic, could expose banking relationships, revenue figures or contractual terms that aid further targeting of the company or its partners. Because the number of people affected is unknown, it is impossible to quantify how many employees or associates may need to take protective steps.
For Evasa itself, the listing creates operational and reputational pressure even without confirmed encryption downtime. Clients and regulators may seek assurances about data-handling practices; staff may face elevated phishing risk; and any subsequent publication of the files would amplify those effects. All such consequences remain contingent on the accuracy of the group’s claims, which have not been independently verified in the public record.
What to do if you're exposed
If you are a current or former employee or otherwise believe your information may have been among the files frag claims to hold, begin with basic hygiene: monitor bank and credit accounts for unfamiliar activity, enable multi-factor authentication on email and financial services, and consider placing a fraud alert or credit freeze where available in your jurisdiction. Replace any passwords that may have been reused across work and personal accounts. If identity documents such as a passport or DNI were stored by the company, contact the issuing authority for guidance on reporting potential compromise.
Because the full scope remains unconfirmed, treat any unsolicited contact that references Evasa or personal details as suspicious. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets; such a check provides an additional, independent signal while official notifications, if any, are still pending.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Nelson Law Firm Listed by frag Ransomware GroupSouthwest Inspection and Testing Listed by frag Ransomware GroupCryoviva Listed by frag Ransomware GroupSource Photonics Listed by frag Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Evasa Listed by frag Ransomware Group →
Publicly posted by frag — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.