River Financial Corporation

River Financial Corporation confirmed unauthorized access, ransomware deployment and removal of data from its network, including River Bank & Trust. A July 30 SEC amendment said River attempted to suppress the affected data and obtained the threat actor’s representation that the stolen data was deleted. River did not say deletion was verified or disclose a ransom payment, and the affected information and potential materiality remain unresolved.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
Unauthorized access to systems, accounts, networks, or data.
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
Internal business, administrative, operational, or staff-facing systems were unavailable.
The incident may involve extortion, but available evidence does not establish which extortion indicators were present.
River Financial Corporation confirmed in a June 25, 2026 Form 8-K that an unauthorized actor accessed its network, including River Bank & Trust, on or about June 16 and deployed ransomware across portions of its server environment. River identified the activity June 19, disabled affected administrative accounts, took impacted systems offline and engaged forensic and cybersecurity specialists.
A July 10 amendment confirmed that the actor accessed portions of the network and removed data. River had not identified the information involved or whether customer personally identifiable information was affected, and it reported no known fraud directly resulting from the incident.
In a July 30 amendment, River said it took steps to attempt to suppress the affected data, including obtaining representations from the threat actor that it deleted the data in its possession. That statement confirms an actor assurance, not verified deletion. It does not establish that no other copies exist, reverse the confirmed exfiltration, or resolve whether personal information was involved.
SecurityWeek reported that the filing’s wording likely reflected a ransom payment. River did not disclose a payment, payment amount, negotiation terms or how it obtained the representation. DysruptionHub therefore treats payment as an unconfirmed inference and retains unknown extortion indicators.
The June 25 filing said certain operations were affected and restoration was ongoing. That supports a partial operational outage and internal-system unavailability, but River did not identify impacts to branches, ATMs, online or mobile banking, wires, cards, telephone systems, cash management or loan services.
The July 6, July 10, July 17 and July 30 amendments expanded the investigation, data-response and litigation record. They did not state that operations or systems remained unavailable on those filing dates. Investigation, efforts to suppress stolen data, unresolved materiality and lawsuits are downstream consequences and do not extend the operational clock without evidence of continuing disruption.
June 25 remains the latest confirmed operational-impact date. Forty calendar days had elapsed by August 4 without a newer operational observation, so the incident remains presumed resolved. River has not published an operational all-clear or full-restoration date, preventing a resolved assessment.
Confidence is high that this was ransomware because River directly confirmed unauthorized access and ransomware deployment. Unauthorized data access and removal are also confirmed at a general level, while the affected data, population and notification scope remain unresolved.
Confidence is low that the stolen data was actually deleted. The only public basis is the unidentified threat actor’s representation relayed by River, and no reviewed source describes independent verification. No reliable public source identifies the actor or establishes a ransom demand, negotiation, payment, leak threat or data publication.
The public record does not identify the access vector, ransomware family, affected systems, encryption scope, persistence, recovery method or full-restoration date. It also does not establish which operations were affected after detection, what data was removed, whether customer or employee personal information was acquired, whether a ransom was paid, how the threat actor’s deletion representation was obtained, whether deletion was verified or whether other copies remain.


DysruptionHub reported River’s ransomware disclosure and noted that the company did not identify impacts to branches, ATMs, online or mobile banking, wires, cards, telephone systems, cash management or loan services. No public ransomware-group claim was identified at publication.
River confirmed unauthorized access to its network, including River Bank & Trust, ransomware deployment across portions of its server environment, affected operations, containment actions and ongoing restoration.
River said certain data was potentially impacted, it was assessing whether personally identifiable information was affected, and it had no evidence that accounts were impacted.
River confirmed that the actor accessed portions of its network and removed certain data, reported no known fraud directly resulting from the incident, disclosed two related class actions and said the full scope, impact and potential materiality remained unresolved.
River reported four class actions related to the incident. It said the principal issue in each was whether cybercriminals acquired customers’ personally identifiable information, while the incident’s full nature, scope, impact and potential materiality remained unresolved.
River said it attempted to suppress the affected data and obtained representations from the threat actor that it deleted the data in its possession. River said the incident’s full nature, scope and impact remained undetermined and it had not determined whether personally identifiable information was affected or whether the incident was reasonably likely to materially affect the company.
SecurityWeek reported River’s July 30 statement that it obtained threat-actor representations that stolen data was deleted. The outlet inferred that the filing’s wording likely reflected a ransom payment, while noting that River had not shared details about the actor or attack.
Signed-in members can report an error, update, or missing source.