Jul 31, 2026
Policy

River Bank ransomware filing says hackers claimed they deleted stolen data

River Financial told the SEC it sought deletion assurances from its ransomware attacker, while lawsuits and its investigation remain unresolved.

Renata Fuchs

By Renata Fuchs · Policy Reporter

· 3 min read

River Bank ransomware filing says hackers claimed they deleted stolen data
Photo: The Register

River Financial Corporation told the Securities and Exchange Commission that, in the River Bank ransomware incident, it obtained assurances from the attacker that stolen data had been deleted. The company did not disclose whether it paid a ransom, did not give a cost estimate for the incident and said its investigation is still unfinished, leaving investors and affected customers without a confirmed account of the breach’s scope.

In a Form 8-K filing, River said it had “took steps to attempt to suppress the affected data,” including receiving representations from the threat actor that the data in its possession had been deleted. That phrasing matters because ransomware groups often use claimed deletion as part of extortion negotiations, while victims have limited ways to verify what was copied, retained or resold.

River did not state in the filing whether money changed hands. The Register reported that it asked the company for a clearer answer on whether it paid any ransom demand, and said River did not immediately respond.

What happened in the River Bank ransomware attack?

River first disclosed the incident to the SEC on June 16, saying ransomware had been deployed on parts of its server environment. The company said it took affected systems offline, disabled administrative accounts and brought in outside incident response specialists to determine what had happened.

By July 6, the company’s filings indicated that some data may have been affected. Four days later, River said certain data had been removed from its environment. By July 10, the company knew data had been taken, and two class action lawsuits had already been filed against it.

One week after that, River told investors that two more class actions had been filed, bringing the total to four. The company’s most recent filing says the investigation has not been completed, so River has not confirmed the full scope or impact of the attack.

Why deletion promises are weak comfort

A ransomware attacker’s claim that it deleted stolen data is difficult to treat as a reliable control. The issue is not only whether a victim paid, but whether the victim can prove the attacker did not keep copies, share them with affiliates or lose control of them inside a criminal marketplace.

There is precedent for skepticism. When law enforcement disrupted the LockBit ransomware operation in 2024, investigators found evidence that victim data had been retained even after some victims paid extortion demands. That history undercuts the value of deletion assurances as a risk reducer, particularly for regulated companies that have to explain incidents to investors, customers and courts.

River’s filings leave several material questions unanswered: whether a ransom was paid, what categories of data were removed, how many people or accounts were affected, and what financial exposure the company may face from incident response, litigation or remediation. For now, the bank has told regulators it tried to limit the data’s exposure and obtained a deletion representation from the attacker. It has not said enough to show that the data is gone.

This story draws on original reporting from The Register.

More from Policy

All Policy →