Skip to content
Beveiligingsnieuws

River Bank ransomware: stolen data reportedly deleted

ransomware gestolen data

River Financial Corporation, the holding company behind River Bank & Trust, says it received confirmation that the data stolen in a ransomware attack was deleted. The disclosure, made through filings with the U.S. Securities and Exchange Commission (SEC), adds one more piece to an incident that is still unfolding in terms of impact, scope, and potential exposure of personal information.

The company’s statements describe how the attack was discovered after it started, what steps it took immediately afterward, and what remains uncertain as investigators continue their work.

Timeline of the ransomware incident

According to River’s disclosures, the ransomware attack took place on June 16. The company identified the intrusion three days later, on June 19. Once it became aware of the incident, River began investigating how the ransomware reached parts of its server environment and what data may have been involved.

River states that its investigation found ransomware was deployed across portions of its server infrastructure. In response, the organization moved quickly to reduce risk by taking affected systems offline.

Immediate containment and access changes

Beyond shutting down impacted systems, River also disabled administrative accounts that it determined had been compromised. This kind of access restriction is commonly used to limit an attacker’s ability to maintain control or continue moving through networks.

At the same time, River worked with a third-party forensic firm to understand the nature and extent of the activity. The goal, as the company described it, is to clarify both what happened and what information—if any—was subject to unauthorized access or exfiltration.

What River told the SEC about data theft

In subsequent 8-K forms filed with the SEC, River reported that hackers accessed parts of its network and exfiltrated certain data. The filings also note that at least four lawsuits had been filed against the company.

Even with these acknowledgments, River emphasized that its assessment process was still in motion. A later filing dated July 30 indicates the company had not yet determined whether the attackers stole personal information from its systems.

Confirming that stolen data was deleted

One of the most notable details in River’s disclosures is its claim that it obtained confirmation that the stolen data was deleted. The company describes steps taken as part of its response to suppress the affected data.

River’s filing indicates it obtained representations from the threat actor stating that the data in the attacker’s possession was deleted. While River does not provide detailed specifics about how that confirmation was verified, the wording suggests the company engaged with the attackers to resolve the threat related to the exfiltrated files.

For customers and observers, this kind of statement can be meaningful, but it also leaves open questions. Deletion claims do not always eliminate residual risk—especially if data was accessed previously or copied—so many organizations continue to evaluate whether any personal data was impacted even after removal actions are asserted.

Unclear responsibility and unclear intrusion path

River did not share details about the threat actor behind the ransomware incident. It also did not clarify how the attackers compromised its network in the first place.

This uncertainty matters because the initial access method can influence which systems were exposed, what attacker tools were used, and how much lateral movement may have occurred. Until the investigation provides more clarity, River’s understanding of the full chain of events remains incomplete.

Ongoing investigation into business impact

In its filings, River also states that it had not confirmed whether the incident was reasonably likely to materially impact its business or financial condition. That statement reflects a common reality in breach response: early disclosures often focus on containment and investigation, while a fuller view of costs, regulatory exposure, and operational disruption can take longer to confirm.

River also indicated that it was investigating the “nature and scope” of the incident, including the possible access or exfiltration of personally identifiable information.

Why lawsuits may continue even after deletion claims

River’s SEC disclosures mention that at least four lawsuits were filed. Even if a company later reports that stolen data was deleted, legal cases may proceed based on allegations such as inadequate security, delayed detection, or exposure concerns.

In ransomware incidents, affected parties often argue that the mere occurrence of unauthorized access—regardless of what ultimately happened to the data—can create harms ranging from compliance failures to customer impacts.

What customers and organizations should watch for

While the filing offers a key update—stolen data reportedly deleted—River’s disclosures also show that several points remain under review. The company had not yet determined whether personal information was stolen, and it continued to assess the overall impact of the incident.

If you are an employee, customer, or partner of a financial institution, it’s worth paying attention to subsequent updates. Breach response often includes additional communications, risk assessments, and potential remediations after the initial incident is contained.

Media follow-up and potential future updates

SecurityWeek reported that it emailed River for more details about the ransomware attack and said it would update the article if the company responded. That means additional clarity may emerge beyond what is currently stated in the SEC filings.

For now, River’s public disclosures focus on what it knows: the timeframe of the attack, initial containment actions, confirmation that stolen data was deleted, and the remaining uncertainty around personal information exposure and business impact.

Conclusion

River Bank’s parent company says it received confirmation that stolen data was deleted after a ransomware attack detected in late June. Through SEC filings, the organization described containment steps such as taking affected systems offline and disabling compromised administrative accounts, while also noting ongoing investigation into personal information exposure and broader business impact.

Even with a deletion confirmation, River’s reporting shows that the case is not fully closed. As investigations continue and more details potentially come to light, the focus will likely remain on verifying what data was accessed, whether personally identifiable information was involved, and how the incident affects customers, compliance obligations, and financial outcomes.

Source: https://www.securityweek.com/river-bank-says-hackers-deleted-data-stolen-in-ransomware-attack/