River Bank Reports Ransomware Attack Resulting in Data Deletion
River Financial Corporation confirmed that data stolen in a ransomware attack was deleted, following legal actions and ongoing investigations.
Company Confirmation
River Financial Corporation, the parent company of River Bank & Trust, confirmed that data stolen during a ransomware attack was deleted. The breach occurred on June 16 and was detected three days later. The investigation revealed that ransomware was deployed across parts of the organization’s server infrastructure. Affected systems were isolated, and compromised administrative accounts were disabled.
Breach Timeline
A June 25 filing with the U.S. Securities and Exchange Commission (SEC) stated that a third-party forensic firm is examining the incident to determine if personally identifiable information was accessed or stolen. Subsequent 8-K filings indicated that attackers gained access to network segments and exfiltrated specific data, leading to at least four legal actions against the company.
SEC Filings and Legal Actions
A July 30 SEC filing noted that the company had not yet determined if personal information was compromised. The document also mentioned that the organization engaged with the threat actors to secure the deletion of stolen data, likely following a ransom payment. “River implemented measures to suppress the affected data, including receiving assurances from the threat actor that the data in their possession was deleted,” the company stated.
Investigation and Transparency Concerns
Details about the threat group responsible for the attack remain undisclosed, as does the method used to breach the network. The company has not confirmed whether the incident could significantly affect its operations or financial standing. SecurityWeek contacted River for further information on the ransomware attack and will update the report if additional details are provided.
Ongoing Investigation
The investigation into the breach’s scope and consequences is ongoing. Initial findings suggest that attackers accessed network segments and extracted data, though the full extent of the compromise is unclear. Legal actions have already been initiated, highlighting the severity of the incident.
Company Response and Challenges
The company’s efforts to recover and mitigate the damage include collaboration with cybersecurity experts and communication with the perpetrators to ensure data deletion. However, the lack of transparency regarding the threat actor’s identity and attack vector raises concerns about the incident’s broader implications. River has not yet assessed whether the breach will have a material impact on its business or financial health.
Conclusion
The situation underscores the challenges organizations face in responding to ransomware attacks, particularly when dealing with unknown adversaries and unverified data deletion claims.
