River Financial Corporation says the attackers who breached its network in June have 'represented' that the stolen data was deleted — which is not the same thing as proof.
On June 16, 2026, someone got into River Financial Corporation's network, deployed ransomware across parts of its server environment, and stole data before anyone at the bank knew it was happening. River, the holding company behind River Bank & Trust, says it found out three days later, on June 19. What it told the SEC in a follow-up filing on July 30 is the part worth pausing on: its main evidence the stolen data is gone is that the attackers said so.
What actually happened, in order
June 16, 2026
An unauthorized threat actor gains access to River Financial Corporation's network environment.
June 19, 2026
River identifies the activity and determines ransomware was deployed across portions of its server environment; affected systems are taken offline and compromised admin accounts disabled.
June 25, 2026
River files its first SEC Form 8-K disclosing the incident.
July 30, 2026
A follow-up 8-K states the investigation is ongoing and River has not determined if the incident is 'reasonably likely to materially impact' the business.
Early August 2026
At least four lawsuits have been filed; River says it obtained representations from the attacker that the stolen data was deleted.
What a 'representation' from a ransomware gang is actually worth
This is the part of the filing doing the most work with the least substance. 'Representations from the threat actor' is standard language for what happens during ransomware negotiations — the victim pays or negotiates, and the attacker sends some form of assurance, sometimes a screen recording of a deletion, sometimes just a message, that the stolen copy is gone. There is no independent way to verify any of it. The attacker still has whatever backups they made before 'deleting' anything, and nothing stops the same group from reselling or leaking the data regardless of what they promised, since there's no enforcement mechanism against a criminal group operating outside any jurisdiction that would prosecute them for lying to a bank.
River hasn't named the threat actor responsible, which is itself notable — most groups that operate leak sites publicize a victim specifically because the threat of publication is the leverage. A quiet negotiation without a named group suggests River may be dealing with an actor that prefers off-the-record extortion to public shaming, which is its own kind of concerning.
The legal fallout is already ahead of the facts
Four lawsuits is a fast number for a bank that still hasn't confirmed whether personal information was actually taken. That's how post-breach litigation works now — plaintiffs' firms file as soon as an 8-K exists, often before the company itself knows the scope, because the statute-of-limitations clock and the risk of being second-to-file both favor speed over certainty. River's own filings admit as much: as of the July 30 update, the company still hadn't determined whether the incident is 'reasonably likely to materially impact its business or financial condition' — the exact phrase the SEC's 2023 cyber-disclosure rule requires public companies to assess.
River Bank & Trust is a community bank — a category ransomware crews have leaned into for weaker security budgets than national banks. · Unsplash
This is part of a bigger pattern
River Bank isn't an isolated case this summer. CareCloud's breach notification took four months to reach patients after the healthcare billing company discovered it. MCBS leaked 1.26 million records through a billing vendor most patients had never heard of. Allstate's breach claim is still unresolved on scope, months after the ransomware group's initial claim. The pattern across all of them: the actual number of people affected and the real content of what was stolen takes weeks to months to surface, if it surfaces at all, while the company's public statements stay carefully vague on both.
What is River Bank & Trust?
River Bank & Trust is a community bank operated by River Financial Corporation, a publicly traded bank holding company that disclosed the ransomware attack via SEC filings.
Was customer data confirmed stolen?
As of River's July 30, 2026 filing, the company had not confirmed whether personally identifiable information was subject to unauthorized access or exfiltration — the investigation was still ongoing.
Can you trust a ransomware group's promise to delete stolen data?
No independent verification exists for these promises. The attacker retains full technical ability to keep, sell, or leak the data regardless of what it represented, since there's no enforcement mechanism against a criminal group.
How many lawsuits have been filed against River?
At least four lawsuits had been filed against River Financial Corporation as of early August 2026.
River's next scheduled disclosure point is whatever the investigation turns up next, and given the July 30 filing still had no concrete numbers six weeks after detection, don't expect fast answers. If you bank with River Bank & Trust, the practical move is the same one that applies to every breach with an unconfirmed scope: watch your statements, freeze your credit if you're not already using one, and don't take a company's careful language as anything stronger than 'we haven't looked hard enough to find it yet.'