River Bank Paid Hackers to Delete Stolen Data After June Ransomware Attack
Alabama's River Bank & Trust was hit by ransomware in June. The bank appears to have paid the criminals to destroy what they took, but still cannot confirm whether customer data was exposed.

Key points
- River Bank & Trust's parent company, River Financial Corporation, discovered a ransomware attack on June 19, 2025, three days after criminals broke into its systems on June 16.
- The bank filed at least three separate disclosures with the U.S. Securities and Exchange Commission between June 25 and July 30, 2025, as required by new federal rules on cyber incident reporting.
- Criminals removed data from the bank's servers; the bank then obtained a written promise from the hackers that the stolen data was deleted, strongly suggesting a ransom was paid.
- As of the July 30 filing, the bank had not confirmed whether any customer personal information was among the stolen files.
- At least four lawsuits have been filed against River Financial Corporation over the incident.
River Financial Corporation, the holding company that owns River Bank & Trust in Alabama, has told federal regulators that it obtained a promise from the criminals behind a June ransomware attack that they deleted the data they stole. Ransomware is malicious software that locks a company's computer files until a payment is made. The bank's admission points strongly toward a ransom payment, though the company has not said so explicitly.
The attack began on June 16. Bank staff identified it three days later, on June 19.
What did the bank tell regulators?
Federal securities law now requires publicly listed companies to report significant cyber incidents quickly. River filed its first 8-K form, a standard SEC disclosure document used to report unexpected events, on June 25. That filing said the bank was still working out whether any personal information had been accessed or removed.
Later filings told a starker story. Criminals had accessed portions of the bank's internal network and removed certain files. By the July 30 filing, the bank still could not confirm whether personal details belonging to customers were in those files.
The July 30 filing contained one particularly notable sentence: "River took steps to attempt to suppress the affected data, including obtaining representations from the threat actor that it deleted the data in its possession." In plain terms, the bank negotiated with the criminals and received their word that the stolen data was destroyed.
Criminal promises of this kind are unverifiable. Security experts consistently note that paying ransoms and accepting deletion assurances gives victims no guarantee the data is truly gone.
Should River Bank customers be worried?
Possibly. The bank has not ruled out that personal information, which could include names, account details, or identifying numbers, was in the stolen files. Customers should watch for any unusual activity on their bank accounts and be alert to phishing attempts, where criminals send fake emails or text messages designed to trick people into handing over passwords or financial details.
If River contacts you directly about the breach, treat that communication carefully: call the bank on its official published number to verify it is genuine before clicking any link or providing any information.
| Event | Date |
|---|---|
| Ransomware deployed on bank systems | June 16, 2025 |
| Incident identified by bank | June 19, 2025 |
| First SEC 8-K disclosure filed | June 25, 2025 |
| Deletion "representation" obtained from hackers | Before July 30, 2025 |
| Most recent SEC filing reviewed | July 30, 2025 |
| Lawsuits filed against the company | At least 4 (as of filing) |
As first reported by SecurityWeek, River has not disclosed which criminal group carried out the attack or how the hackers initially broke in. The bank said it has not yet determined whether the incident will materially affect its business or finances, a specific threshold under SEC cybersecurity disclosure rules finalized in 2023 that triggers mandatory public reporting.



