Ransomware Attack on River Bank & Trust: Data Exfiltration, Suspected Payment, and Four Lawsuits
River Bank & Trust was hit by a ransomware attack causing data exfiltration, suspected ransom payment, system shutdowns, and four ongoing lawsuits.
Illustrative image generated with AI
Systems Shut Down and Accounts Disabled After Detection
On June 16, a ransomware strain hit the internal servers of River Bank & Trust, a subsidiary of River Financial Corporation. The intrusion was discovered only three days later, on June 19. The bank responded by immediately shutting down affected systems and disabling compromised administrative accounts.
An external forensic consultant was engaged to lead the investigation. Quick containment limited lateral movement, but data had already been exfiltrated from the network before the lockdown.
Confirmed Exfiltration and the Shadow of a Payment
SEC filings — the June 25 8-K form and subsequent updates through July 30 — confirm data exfiltration. It is still unclear whether the stolen data includes personal information of customers or employees.
One detail carries disproportionate weight: the company obtained a statement from the threat actor that the stolen data had been deleted. In the absence of verifiable technical guarantees, such an assurance is meaningless. However, the fact that it was requested and received strongly suggests a ransom payment was made. River has never explicitly admitted making one.
Four Lawsuits and an Uncertain Future
At least four lawsuits have now been filed against the company. The reputational damage compounds the operational disruption caused by the system shutdowns. The full financial impact has yet to be quantified.
Many unknowns persist. Any exposure of personal data could trigger notification obligations and aggravate the legal picture. And a criminal group’s deletion promise is no equivalent to certified remediation.
Sources
This article is an original reworking based on the sources below.




