River Financial Corporation ransomware incident
Summary
River Financial Corporation disclosed that an unauthorized actor accessed its network, including River Bank & Trust, on or about June 16, 2026, deployed ransomware across portions of its servers and removed data. Certain operations were affected, but River had not identified the affected services, data categories or customer PII involvement. A July 17 SEC amendment reported four related class actions and said the incident’s full scope, impact and potential materiality remained unresolved.
Key facts
Timeline
-
Incident start:
?
Earliest known or assessed start of malicious activity or incident activity. -
First public signal:
?
Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity. -
First public cyber evidence:
?
Earliest credible public information connecting the incident or disruption to malicious cyber activity. -
Official cyber disclosure:
?
First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related. -
Last impact seen:
?
Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
Impacted location
Primary victim organization
Organization types
Critical infrastructure sector
DysruptionHub coverage
Incident characteristics
Assessments
- Status:
- Presumed Resolved
- Incident confidence:
- High
- Ransomware:
- Confirmed
DD-CIT classification
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Attack mechanisms
-
Ransomware
Malware that encrypts systems or data, typically accompanied by a ransom demand.
-
Unauthorized access
Unauthorized access to systems, accounts, networks, or data.
Data impacts
-
Data theft or exfiltration
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
-
Unauthorized data access
An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.
Operational impacts
-
Partial service outage
A service, system, platform, or operational capability remained available only in part or with significant limitations.
-
Internal systems unavailable
Internal business, administrative, operational, or staff-facing systems were unavailable.
Extortion indicators
-
Unknown extortion indicators
The incident may involve extortion, but available evidence does not establish which extortion indicators were present.
Incident narrative
Analyst assessment
River Financial Corporation confirmed in a June 25, 2026 Form 8-K that an unauthorized actor accessed its network, including River Bank & Trust, on or about June 16 and deployed ransomware across portions of its server environment. River identified the activity June 19, disabled affected administrative accounts, took impacted systems offline and engaged forensic and cybersecurity specialists.
A July 10 amendment confirmed that the actor accessed portions of the network and removed data. River had not identified the information involved or whether customer personally identifiable information was affected, and it reported no known fraud directly resulting from the incident.
Operational significance
The June 25 filing said certain operations were affected and restoration was ongoing. That supports a partial operational outage and internal-system unavailability, but River did not identify impacts to branches, ATMs, online or mobile banking, wires, cards, telephone systems, cash management or loan services.
The July 6, July 10 and July 17 amendments expanded the investigation, data-impact and litigation record. They did not state that operations or systems remained unavailable on those filing dates. Investigation, unresolved materiality and lawsuits are downstream consequences and do not extend the operational clock without evidence of continuing disruption.
Current status
June 25 is the latest confirmed operational-impact date. Thirty-one calendar days had elapsed by July 26 without a newer operational observation, so the incident is presumed resolved. River has not published an operational all-clear or full-restoration date, preventing a resolved assessment.
Confidence and uncertainty
Confidence is high that this was ransomware because River directly confirmed unauthorized access and ransomware deployment. Unauthorized data access and removal are also confirmed at a general level, while the affected data, population and notification scope remain unresolved. No reliable public source identifies the threat actor or establishes a ransom demand, negotiation, payment or leak publication.
Analytic gaps
The public record does not identify the access vector, ransomware family, affected systems, encryption scope, persistence, recovery method or full-restoration date. It also does not establish which operations were affected after detection, what data was removed or whether customer or employee personal information was acquired.
Organizations involved
River Financial Corporation

Locations
Organization type
Critical infrastructure
River Bank & Trust

Locations
Organization type
Critical infrastructure
Impacted location
Prattville, Autauga County, Alabama, USA
Sources
- Type: News Report
- Stance: Report
- Platform: Website
- Medium: Web Page
- Confidence: High
DysruptionHub reported River’s ransomware disclosure and noted that the company did not identify impacts to branches, ATMs, online or mobile banking, wires, cards, telephone systems, cash management or loan services. No public ransomware-group claim was identified at publication.
- Type: Official Statement
- Stance: Confirm
- Platform: Website
- Medium: Document
- Confidence: High
River confirmed unauthorized access to its network, including River Bank & Trust, ransomware deployment across portions of its server environment, affected operations, containment actions and ongoing restoration.
- Type: Official Statement
- Stance: Confirm
- Platform: Website
- Medium: Document
- Confidence: High
River said certain data was potentially impacted, it was assessing whether personally identifiable information was affected, and it had no evidence that accounts were impacted.
- Type: Official Statement
- Stance: Confirm
- Platform: Website
- Medium: Document
- Confidence: High
River confirmed that the actor accessed portions of its network and removed certain data, reported no known fraud directly resulting from the incident, disclosed two related class actions and said the full scope, impact and potential materiality remained unresolved.
- Type: Official Statement
- Stance: Confirm
- Platform: Website
- Medium: Document
- Confidence: High
River reported four class actions related to the incident. It said the principal issue in each was whether cybercriminals acquired customers’ personally identifiable information, while the incident’s full nature, scope, impact and potential materiality remained unresolved.