River Financial Corporation, the parent company of River Bank & Trust, says hackers deleted data stolen during a ransomware attack that hit parts of its server environment in June. The breach began on June 16 and was detected three days later, when the company found ransomware had been deployed on affected systems. While the investigation is still ongoing, the bank says it has received confirmation that the exfiltrated data was deleted.
The financial organization is investigating the incident with help from a third-party forensic firm. At this time, it is unclear whether attackers accessed or stole any personally identifiable information.
“On or about June 16, 2026, an unauthorized threat actor gained access to the network environment of River Financial Corporation, including River Bank & Trust (together, “River”). River identified the activity on or about June 19, 2026, and determined that ransomware had been deployed across portions of its server environment. River promptly took containment measures, including disabling affected administrative accounts and taking impacted systems offline.” reads the FORM 8-K report filed with SEC in June.
“River, with the assistance of a third-party forensic firm, is investigating the nature and scope of the incident, including whether any personally identifiable information was subject to unauthorized access or exfiltration. That investigation is ongoing.”
In a later report, the company confirmed that attackers accessed parts of its network and stole data. The company is still determining what information was affected, including whether personal data was exposed. As part of its response, River says it obtained assurances from the threat actor that the stolen data was deleted. The investigation remains ongoing, and the company has not yet determined the incident’s full business or financial impact.
“As part of its response, River took steps to attempt to suppress the affected data, including obtaining representations from the threat actor that it deleted the data in its possession.” reads a newer FORM 8-K report. “As of the date of this filing, the full nature, scope, and impact of the incident have not yet been determined. River has not yet confirmed whether the incident is reasonably likely to materially impact its business or financial condition. River will file an amendment to this Current Report on Form 8-K within four business days after it determines that such information is available.”
River has not disclosed the name of the threat actor that breached its systems or disclosed how its network was compromised. The company also says it has not yet determined whether the incident will have a material impact on its business or financial condition.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, data breach)