evergreenpnw.com Listed by incransom Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Evergreenpnw.com was listed by the Incransom ransomware group on January 22, 2025, after internal files were exfiltrated in a ransomware attack. The number of people affected has not been disclosed; individuals should verify whether their information was involved and take protective steps if necessary.
People connected to Evergreen Christian Community in Olympia, Washington, may now face questions about whether their personal or organizational information has been taken and could be misused. On January 22, 2025, the ransomware group incransom listed evergreenpnw.com on its leak site, claiming it had exfiltrated internal files in a ransomware attack. The number of people affected remains unknown, and public detail on the full scope is limited, yet any exposure of internal records from a religious organization can create lasting practical risks for members, staff, and partners.
This incident matters because religious communities often hold sensitive contact details, donation records, and internal communications that, if released, can enable fraud, harassment, or further targeting. Without confirmed confirmation beyond the group's listing, the claim itself is the primary public signal that data may have left the organization's control.
Breaking down the breach
According to the available record, evergreenpnw.com was listed by the incransom ransomware group on January 22, 2025. The group claims that internal files were exfiltrated during a ransomware attack. The listing includes a reported total of 63,846 files totaling 32,565,343,182 bytes, along with 16,440 directories and a free-space figure of 7,329,921,945,600 bytes. No independent confirmation of the attack method, exact timing of intrusion, or full verification of the file contents has been disclosed in the public facts. The number of people affected is listed as unknown. Public detail beyond the leak-site claim and these file counts remains limited.
The organization is identified as Evergreen Christian Community, operating in the religious organizations sector, employing between 100 and 249 people, with revenue in the 10 million to 25 million range, and headquartered in Olympia, Washington. Contact numbers associated with the entity, including a main phone line and an IT director line, appear in the same record, but these do not alter the core claim that internal files were taken.
The group behind it: incransom
Incransom is a known ransomware operation that typically encrypts victim systems and simultaneously steals data for double-extortion pressure. Groups of this type publish victim names and sample file listings on dedicated leak sites to coerce payment, often threatening full public release if demands are unmet. Public reporting on incransom has documented its use of standard ransomware tactics: initial access through common vectors such as phishing or exposed services, followed by lateral movement, data theft, and encryption. The group has previously listed organizations across multiple sectors, using the threat of data dumps to increase leverage.
In this case, the listing of evergreenpnw.com is presented as a claim by the group. No additional statements from incransom about this specific victim—beyond the file counts and the assertion of internal-file exfiltration—are included in the available facts. Readers should treat the leak-site entry as an unverified assertion until independent confirmation appears.
Who is evergreenpnw.com?
Evergreen Christian Community is a religious organization based in Olympia, Washington. Entities of this type typically serve congregations, manage community programs, handle donations, and maintain records of members, staff, volunteers, and partners. With a reported staff size of 100 to 249 people and revenue between 10 million and 25 million, it operates at a mid-sized scale within the religious sector. Such organizations commonly hold membership directories, financial contribution data, internal communications, event records, and administrative files necessary for daily operations and pastoral care.
A breach involving a religious community is consequential because trust and confidentiality form part of its core function. Members and staff may have shared personal circumstances, contact information, or financial details under an expectation of privacy. Exposure of those records can affect not only the organization itself but also the wider network of people who interact with it.
What data was at risk
The facts state that internal files were exfiltrated in a ransomware attack. The listing reports 63,846 files totaling roughly 32.5 gigabytes. Exact data types beyond the broad category of “internal files” are not further itemized in the public record, and the precise contents remain unconfirmed. Organizations in the religious sector typically maintain membership lists, donor records, staff personnel files, email archives, financial ledgers, and operational documents. Whether any of those categories were among the files claimed by incransom has not been independently verified. The number of individuals whose information may appear in those files is listed as unknown.
The real-world impact
For people whose data may be included, the practical risks include targeted phishing, identity-related fraud, or unwanted contact that leverages personal details. Even limited internal files can contain enough context—names, addresses, phone numbers, or contribution histories—to make social-engineering attempts more convincing. Staff and volunteers may face additional exposure if personnel or administrative records were among the taken material.
For the organization, the incident creates operational and reputational pressure. Restoring systems after ransomware, investigating the scope of any theft, and communicating with affected parties require time and resources. The leak-site listing itself can generate public concern among members and partners, regardless of whether a full data dump ultimately occurs. Because the number of people affected is unknown and the exact contents unconfirmed, the full extent of downstream harm cannot yet be measured from public information alone.
What to do if you're exposed
If you have a connection to Evergreen Christian Community—as a member, donor, staff member, or partner—treat the possibility of exposure seriously but calmly. Monitor financial accounts and credit reports for unexpected activity. Be cautious of unsolicited emails, calls, or messages that reference the organization or personal details you may have shared with it; verify any such contact through official channels before responding. Consider placing a fraud alert with major credit bureaus if you believe sensitive identifiers could be involved. Change passwords on accounts that may have been linked to organizational systems, and enable multi-factor authentication where available.
Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. This step provides an additional early-warning signal and helps prioritize further protective measures. Stay informed through official statements from the organization rather than relying solely on third-party claims.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
KohaFoods Hawaii Listed by incransom Ransomware Groupgeorgetown-brewing-co Listed by incransom Ransomware GroupMonterey Mushrooms, LLC Listed by incransom Ransomware Groupmillerwoodtradepub.com Listed by incransom Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the evergreenpnw.com Listed by incransom Ransomware Group →
Publicly posted by incransom — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.