Skip to content

River Financial Corporation ransomware incident

Summary

River Financial Corporation logo

River Financial Corporation confirmed unauthorized access, ransomware deployment and removal of data from its network, including River Bank & Trust. A July 30 SEC amendment said River attempted to suppress the affected data and obtained the threat actor’s representation that the stolen data was deleted. River did not say deletion was verified or disclose a ransom payment, and the affected information and potential materiality remain unresolved.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted location

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

Data impacts

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

Extortion indicators

  • Unknown extortion indicators

    The incident may involve extortion, but available evidence does not establish which extortion indicators were present.

Incident narrative

Analyst assessment

River Financial Corporation confirmed in a June 25, 2026 Form 8-K that an unauthorized actor accessed its network, including River Bank & Trust, on or about June 16 and deployed ransomware across portions of its server environment. River identified the activity June 19, disabled affected administrative accounts, took impacted systems offline and engaged forensic and cybersecurity specialists.

A July 10 amendment confirmed that the actor accessed portions of the network and removed data. River had not identified the information involved or whether customer personally identifiable information was affected, and it reported no known fraud directly resulting from the incident.

In a July 30 amendment, River said it took steps to attempt to suppress the affected data, including obtaining representations from the threat actor that it deleted the data in its possession. That statement confirms an actor assurance, not verified deletion. It does not establish that no other copies exist, reverse the confirmed exfiltration, or resolve whether personal information was involved.

SecurityWeek reported that the filing’s wording likely reflected a ransom payment. River did not disclose a payment, payment amount, negotiation terms or how it obtained the representation. DysruptionHub therefore treats payment as an unconfirmed inference and retains unknown extortion indicators.

Operational significance

The June 25 filing said certain operations were affected and restoration was ongoing. That supports a partial operational outage and internal-system unavailability, but River did not identify impacts to branches, ATMs, online or mobile banking, wires, cards, telephone systems, cash management or loan services.

The July 6, July 10, July 17 and July 30 amendments expanded the investigation, data-response and litigation record. They did not state that operations or systems remained unavailable on those filing dates. Investigation, efforts to suppress stolen data, unresolved materiality and lawsuits are downstream consequences and do not extend the operational clock without evidence of continuing disruption.

Current status

June 25 remains the latest confirmed operational-impact date. Forty calendar days had elapsed by August 4 without a newer operational observation, so the incident remains presumed resolved. River has not published an operational all-clear or full-restoration date, preventing a resolved assessment.

Confidence and uncertainty

Confidence is high that this was ransomware because River directly confirmed unauthorized access and ransomware deployment. Unauthorized data access and removal are also confirmed at a general level, while the affected data, population and notification scope remain unresolved.

Confidence is low that the stolen data was actually deleted. The only public basis is the unidentified threat actor’s representation relayed by River, and no reviewed source describes independent verification. No reliable public source identifies the actor or establishes a ransom demand, negotiation, payment, leak threat or data publication.

Analytic gaps

The public record does not identify the access vector, ransomware family, affected systems, encryption scope, persistence, recovery method or full-restoration date. It also does not establish which operations were affected after detection, what data was removed, whether customer or employee personal information was acquired, whether a ransom was paid, how the threat actor’s deletion representation was obtained, whether deletion was verified or whether other copies remain.

Organizations involved

Impacted location

Sources

River Financial Corporation says ransomware disrupted River Bank & Trust operations

DysruptionHub reported River’s ransomware disclosure and noted that the company did not identify impacts to branches, ATMs, online or mobile banking, wires, cards, telephone systems, cash management or loan services. No public ransomware-group claim was identified at publication.

River Financial Corporation Form 8-K

River confirmed unauthorized access to its network, including River Bank & Trust, ransomware deployment across portions of its server environment, affected operations, containment actions and ongoing restoration.

River Financial Corporation Form 8-K/A

River said certain data was potentially impacted, it was assessing whether personally identifiable information was affected, and it had no evidence that accounts were impacted.

River Financial Corporation second Form 8-K/A

River confirmed that the actor accessed portions of its network and removed certain data, reported no known fraud directly resulting from the incident, disclosed two related class actions and said the full scope, impact and potential materiality remained unresolved.

River Financial Corporation third Form 8-K/A

River reported four class actions related to the incident. It said the principal issue in each was whether cybercriminals acquired customers’ personally identifiable information, while the incident’s full nature, scope, impact and potential materiality remained unresolved.

River Financial Corporation fourth Form 8-K/A

River said it attempted to suppress the affected data and obtained representations from the threat actor that it deleted the data in its possession. River said the incident’s full nature, scope and impact remained undetermined and it had not determined whether personally identifiable information was affected or whether the incident was reasonably likely to materially affect the company.

River Bank Says Hackers Deleted Data Stolen in Ransomware Attack

SecurityWeek reported River’s July 30 statement that it obtained threat-actor representations that stolen data was deleted. The outlet inferred that the filing’s wording likely reflected a ransom payment, while noting that River had not shared details about the actor or attack.

See something that needs correction?

Signed-in members can report an error, update, or missing source.