Skip to content

River Financial Corporation ransomware incident

Summary

River Financial Corporation disclosed that an unauthorized actor accessed its network, including River Bank & Trust, on or about June 16, 2026, deployed ransomware across portions of its servers and removed data. Certain operations were affected, but River had not identified the affected services, data categories or customer PII involvement. A July 17 SEC amendment reported four related class actions and said the incident’s full scope, impact and potential materiality remained unresolved.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Impacted location

Primary victim organization

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

Incident confidence:
High
Ransomware:
Confirmed

DD-CIT classification

OC-ODOfficial cyberOfficial disruptionAbout the DD-CIT methodology

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

Data impacts

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

Extortion indicators

  • Unknown extortion indicators

    The incident may involve extortion, but available evidence does not establish which extortion indicators were present.

Incident narrative

Analyst assessment

River Financial Corporation confirmed in a June 25, 2026 Form 8-K that an unauthorized actor accessed its network, including River Bank & Trust, on or about June 16 and deployed ransomware across portions of its server environment. River identified the activity June 19, disabled affected administrative accounts, took impacted systems offline and engaged forensic and cybersecurity specialists.

A July 10 amendment confirmed that the actor accessed portions of the network and removed data. River had not identified the information involved or whether customer personally identifiable information was affected, and it reported no known fraud directly resulting from the incident.

Operational significance

The June 25 filing said certain operations were affected and restoration was ongoing. That supports a partial operational outage and internal-system unavailability, but River did not identify impacts to branches, ATMs, online or mobile banking, wires, cards, telephone systems, cash management or loan services.

The July 6, July 10 and July 17 amendments expanded the investigation, data-impact and litigation record. They did not state that operations or systems remained unavailable on those filing dates. Investigation, unresolved materiality and lawsuits are downstream consequences and do not extend the operational clock without evidence of continuing disruption.

Current status

June 25 is the latest confirmed operational-impact date. Thirty-one calendar days had elapsed by July 26 without a newer operational observation, so the incident is presumed resolved. River has not published an operational all-clear or full-restoration date, preventing a resolved assessment.

Confidence and uncertainty

Confidence is high that this was ransomware because River directly confirmed unauthorized access and ransomware deployment. Unauthorized data access and removal are also confirmed at a general level, while the affected data, population and notification scope remain unresolved. No reliable public source identifies the threat actor or establishes a ransom demand, negotiation, payment or leak publication.

Analytic gaps

The public record does not identify the access vector, ransomware family, affected systems, encryption scope, persistence, recovery method or full-restoration date. It also does not establish which operations were affected after detection, what data was removed or whether customer or employee personal information was acquired.

Organizations involved

Impacted location

Sources

River Financial Corporation says ransomware disrupted River Bank & Trust operations
DysruptionHubBy DysruptionHub StaffPublished: Retrieved:
  • Type: News Report
  • Stance: Report
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

DysruptionHub reported River’s ransomware disclosure and noted that the company did not identify impacts to branches, ATMs, online or mobile banking, wires, cards, telephone systems, cash management or loan services. No public ransomware-group claim was identified at publication.

River Financial Corporation Form 8-K
River Financial Corporation / U.S. Securities and Exchange CommissionPublished: Retrieved:
  • Type: Official Statement
  • Stance: Confirm
  • Platform: Website
  • Medium: Document
  • Confidence: High

River confirmed unauthorized access to its network, including River Bank & Trust, ransomware deployment across portions of its server environment, affected operations, containment actions and ongoing restoration.

River Financial Corporation Form 8-K/A
River Financial Corporation / U.S. Securities and Exchange CommissionPublished: Retrieved:
  • Type: Official Statement
  • Stance: Confirm
  • Platform: Website
  • Medium: Document
  • Confidence: High

River said certain data was potentially impacted, it was assessing whether personally identifiable information was affected, and it had no evidence that accounts were impacted.

River Financial Corporation second Form 8-K/A
River Financial Corporation / U.S. Securities and Exchange CommissionPublished: Retrieved:
  • Type: Official Statement
  • Stance: Confirm
  • Platform: Website
  • Medium: Document
  • Confidence: High

River confirmed that the actor accessed portions of its network and removed certain data, reported no known fraud directly resulting from the incident, disclosed two related class actions and said the full scope, impact and potential materiality remained unresolved.

River Financial Corporation third Form 8-K/A
River Financial Corporation / U.S. Securities and Exchange CommissionPublished: Retrieved:
  • Type: Official Statement
  • Stance: Confirm
  • Platform: Website
  • Medium: Document
  • Confidence: High

River reported four class actions related to the incident. It said the principal issue in each was whether cybercriminals acquired customers’ personally identifiable information, while the incident’s full nature, scope, impact and potential materiality remained unresolved.