evergreen-hotel Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Evergreen-hotel has been listed by the Qilin ransomware group, which claims to have exfiltrated internal files in an attack. The incident was disclosed on 29 May 2025, but the date of the intrusion itself has not been established; anyone who has stayed at or done business with the organisation should check for any notifications and change credentials if advised.
People who have stayed at, worked for, or done business with Evergreen Hospitality Group may now face uncertainty about whether their personal or business information was taken. On May 29, 2025, the organisation known as evergreen-hotel appeared on a listing by the ransomware group qilin, which claimed to have exfiltrated internal files in a ransomware attack. The number of people affected remains unknown, and public detail on the precise contents of those files is limited. For guests, staff, and partners, the practical question is whether contact details, reservation records, or other internal material could now be in the hands of criminals who specialise in extortion and resale.
This incident matters because hospitality companies routinely hold data that can be used for identity fraud, phishing, or further social-engineering attacks. Without confirmed numbers or a full inventory of what was taken, those potentially affected must treat the claim seriously while waiting for clearer official information.
Breaking down the breach
According to the available record, evergreen-hotel was listed by the qilin ransomware group on May 29, 2025. The listing asserts that internal files were exfiltrated during a ransomware attack. No public confirmation of the attack’s success, the exact date of intrusion, the volume of data, or any ransom demand has been provided in the facts. The number of people affected is listed as unknown. Method of initial access, duration of the intrusion, and whether systems were encrypted in addition to data theft are all undisclosed.
What is known is limited to the group’s claim of exfiltration of internal files and the organisation’s appearance on the leak site. Until the company or independent investigators release further verified details, the scale and full impact remain unconfirmed.
Who is qilin?
Qilin is a ransomware group that has operated as a ransomware-as-a-service (RaaS) operation. Public reporting on the group describes a double-extortion model: operators encrypt systems and simultaneously steal data, then threaten to publish or sell the material if a ransom is not paid. Affiliates typically handle the intrusion and deployment while the core group manages the leak site and negotiations. The group has been observed targeting organisations across multiple sectors, including hospitality, manufacturing, and professional services, and has listed victims on its dark-web portal as a pressure tactic.
In this case, the listing of evergreen-hotel is a claim by the group. No independent verification of the specific files or the success of the attack against this victim is contained in the available facts. Readers should treat the leak-site entry as an unverified assertion until corroborated by the organisation or trusted third parties.
Who is evergreen-hotel?
Evergreen Hospitality Group is described as one of British Columbia’s largest family-owned hospitality and tourism companies. It operates a variety of accommodations across 26 destinations and presents itself as dedicated to showcasing the region’s beauty to guests. Organisations of this type manage hotels, resorts, and related tourism services; they typically maintain reservation systems, guest profiles, employee records, supplier contracts, and internal operational documents.
A breach involving such a company is consequential because hospitality businesses sit at the intersection of personal travel data, payment information, and staff records. Guests may have provided names, contact details, loyalty information, and sometimes passport or identification data for check-in. Employees and contractors may have payroll, tax, and human-resources files stored internally. Even when payment card data is tokenised or handled by third parties, supporting internal files can still contain enough material to enable targeted fraud or further attacks.
The information in question
The facts state that internal files were exfiltrated in a ransomware attack. No more granular list of data types—such as guest names, email addresses, phone numbers, reservation histories, employee records, or financial documents—has been publicly disclosed. Exact contents therefore remain unconfirmed.
Organisations in the hospitality and tourism sector commonly hold guest contact and booking information, loyalty-programme details, staff personal data, vendor contracts, and operational documents. Whether any of those categories were among the files claimed by qilin is not established in the available record. Until the company issues a verified inventory or regulators publish findings, the precise nature of the exposed material cannot be stated as fact.
What's at stake
For individuals, the primary risks are identity-related fraud, phishing, and social-engineering attempts that use real internal context to appear legitimate. Someone who stayed at one of the properties or worked for the group could receive convincing messages that reference actual stays, employment details, or internal processes. Criminals may also attempt to open accounts, file fraudulent claims, or sell the data onward. Because the number of people affected is unknown, the breadth of exposure cannot yet be measured.
For the organisation, the stakes include operational disruption, potential regulatory scrutiny under Canadian privacy law, reputational damage among guests and partners, and the cost of investigation, notification, and remediation. Even if systems were restored, the mere claim of data theft can erode trust and invite further targeting. None of these outcomes has been confirmed as having materialised; they represent the ordinary consequences that follow ransomware listings of this kind.
What to do if you're exposed
If you have been a guest, employee, or business partner of Evergreen Hospitality Group, begin by monitoring financial accounts and credit reports for unexpected activity. Enable multi-factor authentication on email and any accounts that reuse passwords you may have used with the company. Be sceptical of unsolicited messages that claim to relate to a stay, refund, or employment matter; verify through official channels rather than links or phone numbers supplied in the message. Consider placing a fraud alert with credit bureaus if you believe sensitive personal data may have been involved.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. That step will not confirm or rule out involvement in this specific incident, but it can surface other exposures that warrant attention. Stay alert for any official notification from the company itself, which remains the most reliable source of Reported Details about what, if anything, was taken.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Watermark Beach Resort Listed by qilin Ransomware GroupMusée du Bas-Saint-Laurent Listed by qilin Ransomware GroupQuestica Listed by qilin Ransomware GroupBusbusbus Listed by qilin Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the evergreen-hotel Listed by qilin Ransomware Group →
Publicly posted by qilin — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.