River Financial Corporation disclosed that a June ransomware attack hit portions of the server environment supporting River Bank & Trust, with the intrusion beginning around June 16 and detected around June 19. The attackers accessed parts of the network, exfiltrated data, and deployed ransomware, prompting the company to take affected systems offline and disable compromised administrative accounts while it investigated the breach.
In a July 30 filing, River said it obtained representations from the threat actor that the stolen data had been deleted, indicating some level of engagement with the attackers, but the company has not publicly identified the group or explained the initial access vector. River also said it has not yet determined whether personally identifiable information was accessed or whether the incident is reasonably likely to have a material impact on its business or financial condition, while at least four lawsuits have already been filed in connection with the attack.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
In a July 30 SEC filing, River said it had taken steps to suppress the affected data and obtained representations from the threat actor that the stolen data in the attacker's possession had been deleted. The company said its investigation was still ongoing and it had not yet determined whether personal information was stolen.
In a June 25 SEC filing, River said it was investigating the nature and scope of the incident with help from a third-party forensic firm. The company also said it was assessing whether personally identifiable information had been accessed or exfiltrated.
River identified the malicious activity about three days later and determined that ransomware had been deployed across portions of its server environment. In response, it took affected systems offline and disabled compromised administrative accounts.
River Financial Corporation said an unauthorized threat actor accessed portions of its network environment, including systems affecting River Bank & Trust. The intrusion began on or about June 16, 2026.
Court actions followed the breach, with at least four lawsuits filed against River Financial Corporation in connection with the ransomware incident. The references do not specify the filing dates of the suits.
Subsequent SEC filings revealed that attackers had accessed portions of River's network and exfiltrated certain data from its environment. These filings expanded the known impact beyond ransomware deployment alone.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourceteiss.co.uk
Open sourcesecurityaffairs.com
Open sourcesecurityweek.com
Open sourcesec.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.