river bank got ransomwared, then did something wild: it trusted the hackers' word

River Financial Corporation says the attackers who breached its network in June have 'represented' that the stolen data was deleted — which is not…

Aliteq
Priya Nair · Software & Systems Editor

The short version

Attackers gained network access on or about June 16, 2026; River detected the ransomware deployment on June 19.

The short version

River disclosed the incident in an SEC Form 8-K on June 25, with a follow-up 8-K on July 30 confirming the investigation is still open.

The short version

River says it obtained 'representations from the threat actor that it deleted the data in its possession' — the attacker's word, not independent verification.

The short version

At least four lawsuits have already been filed against River over the breach.

The short version

River has not yet said whether personal information was exfiltrated, how many customers are affected, or which ransomware group was responsible.

My honest take

Paying for a deletion promise from a criminal enterprise isn't security, it's damage-control theater that happens to be standard industry practice. I understand why banks do it — it's cheaper than…

Aliteq

Read the full story

river bank got ransomwared, then did something wild: it trusted the hackers' word

Read the full story on Aliteq