River Bank Confirms Hackers Deleted Stolen Data After Ransomware Attack
River Bank & Trust disclosed that data stolen during a June ransomware attack was deleted by the attackers, though the motive remains unclear.

River Financial Corporation, the bank holding company for River Bank & Trust, has confirmed that data exfiltrated during a ransomware attack in June has since been deleted by the perpetrators. The incident, which began on June 16 and was detected three days later, saw ransomware deployed across portions of the bank's server environment. In response, River took affected systems offline and secured compromised administrative accounts.
An ongoing investigation, aided by a third-party forensic firm, has been working to determine the full nature and scope of the breach, specifically whether any personally identifiable information (PII) was accessed or stolen. Initial filings with the U.S. Securities and Exchange Commission (SEC) on June 25 indicated that hackers had gained access to parts of River's network and exfiltrated certain data. This led to the filing of at least four lawsuits against the company.
Despite these developments, a subsequent filing on July 30 revealed that River had not yet definitively confirmed if any personal information was compromised. However, the wording of the filing suggests that the bank engaged with the threat actors, likely through a ransom payment, to ensure the deletion of the stolen data. "As part of its response, River took steps to attempt to suppress the affected data, including obtaining representations from the threat actor that it deleted the data in its possession," the company stated.
The identity of the threat actor responsible for the attack remains unknown, and the method by which they initially compromised River's network has not been disclosed. The bank has also not yet confirmed whether the incident is likely to have a material impact on its business or financial condition. SecurityWeek has reached out to River for further details and will provide updates as they become available.
This incident highlights a complex and evolving ransomware landscape where attackers may not always monetize stolen data through public leaks. The decision to delete exfiltrated data, even after a successful breach and potential ransom payment, introduces a new layer of uncertainty for victims. It raises questions about the threat actors' motives, which could range from avoiding detection to strategic manipulation, and underscores the challenges in fully assessing the damage and risk following such attacks.
While the immediate threat of data exposure may have been mitigated by the deletion, the underlying vulnerabilities that allowed the initial compromise and data exfiltration still need to be addressed. Organizations like River Bank must continue to fortify their defenses against ransomware, focusing on robust incident response plans, secure data handling practices, and thorough post-incident analysis to prevent future occurrences. The ongoing investigation will be crucial in understanding the full ramifications and ensuring accountability.