River Bank: Stolen Data Deleted After June Ransomware Attack

River Bank reports data taken in a June 16 ransomware attack was deleted after it obtained representations from the threat actor; the probe into the breach and its impact continues.

River Financial Corporation, the holding company for River Bank & Trust, reported that data taken in a June 16 ransomware incident was deleted after the company obtained representations from the threat actor. The attack was discovered three days later.

Company filings show ransomware was deployed across portions of the bank’s server environment. In response, the bank took affected systems offline and disabled administrative accounts that had been compromised.

River engaged a third-party forensic firm to investigate the incident and to determine whether any personally identifiable information was accessed or removed. A June 25 filing with the U.S. Securities and Exchange Commission states, “River, with the assistance of a third-party forensic firm, is investigating the nature and scope of the incident, including whether any personally identifiable information was subject to unauthorized access or exfiltration.”

Later 8-K filings revealed that attackers accessed parts of River’s network and removed certain data. Those filings also show at least four lawsuits have been filed against the company following the breach. A July 30 update indicated River had not yet determined whether personal information was taken or whether the incident would materially affect the company’s business or financial condition.

The filings describe steps taken to try to suppress the stolen data, including obtaining representations from the threat actor that the data had been deleted. The filings do not identify the threat actor, explain how the network was compromised, or state whether any payment was made to secure the deletion claim.

River has not provided a public timeline for completing the investigation or for issuing more detailed findings. The company continues to assess the scope and impact of the incident and is communicating updates through regulatory filings and external advisors.

Articles by this author