River Financial Corporation, the holding company for River Bank & Trust, announced that data exfiltrated during a ransomware attack has been deleted by the attackers. The incident, which began on June 16 and was identified three days later, involved the deployment of ransomware across parts of the bank's server environment. Affected systems were taken offline, and compromised administrative accounts were disabled.
River, with assistance from a third-party forensic firm, is investigating the scope of the incident, including whether personally identifiable information was accessed or stolen. Filings with the US Securities and Exchange Commission (SEC) indicate that hackers accessed portions of River’s network and exfiltrated data. At least four lawsuits have been filed against the company following the attack. As of a July 30 filing, River has not confirmed if personal information was stolen.
The company engaged with the threat actor to ensure the deletion of the stolen data, which likely involved a ransom payment. River stated it "obtained representations from the threat actor that it deleted the data in its possession." Details regarding the identity of the threat actor or how the network was compromised have not been disclosed.
River has not yet determined if the ransomware incident will materially impact its business or financial condition. The investigation remains ongoing to fully assess the consequences of the attack.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
River Financial Corporation confirmed that data stolen during a June 16 ransomware attack was deleted by the threat actor. The company engaged with the hackers to ensure data deletion, likely involving a ransom payment, but has not confirmed if personal information was exfiltrated or the attack's material impact.