River Bank Paid Hackers to Delete Stolen Data After June Ransomware Attack

Alabama's River Bank & Trust was hit by ransomware in June. The bank appears to have paid the criminals to destroy what they took, but still can't confirm whether customer data was exposed.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge
Share

Key points

  • The bank filed multiple disclosures with the U.S. Securities and Exchange Commission between June 25 and July 30, 2025, as required by federal rules on cyber incident reporting.
  • Criminals removed data from the bank's servers; the bank then obtained a written promise from the hackers that the stolen data was deleted, strongly suggesting a ransom was paid.
  • As of the July 30 filing, the bank hadn't confirmed whether any customer personal information was among the stolen files.
  • At least four lawsuits have been filed against River Financial Corporation over the incident.

River Financial Corporation, the holding company that owns River Bank & Trust in Alabama, has told federal regulators it obtained a promise from the criminals behind a June ransomware attack that they deleted the data they stole. Ransomware is malicious software that locks a company's files until a payment is made. The company hasn't said explicitly that it paid a ransom, but the admission points in that direction.

The attack began June 16.

What did the bank tell regulators?

Federal securities law requires publicly listed companies to report significant cyber incidents quickly. River filed its first 8-K form, a standard SEC disclosure used to report unexpected events, on June 25. That filing said the bank was still working out whether any personal information had been accessed or removed.

Later filings told a starker story. Criminals had accessed portions of the bank's internal network and taken certain files. By the July 30 filing, the bank still couldn't confirm whether customers' personal details were among them.

That July 30 filing contained one sentence worth reading carefully: "River took steps to attempt to suppress the affected data, including obtaining representations from the threat actor that it deleted the data in its possession." The bank negotiated with the criminals and accepted their word that the stolen data was gone.

Criminal promises of this kind are unverifiable. Paying a ransom and accepting a deletion assurance gives a victim no guarantee the data is truly destroyed. Our 30 July report on Analog Devices showed exactly that dynamic: a separate extortion group surfaced weeks after the company believed the matter closed.

Should River Bank customers be worried?

Possibly. The bank hasn't ruled out that personal information was in the stolen files. Watch for unusual activity on your accounts and be alert to phishing attempts, where criminals send fake messages designed to trick people into surrendering passwords or financial details.

If River contacts you about the breach, verify it's genuine by calling the bank's official published number before clicking any link or providing any information.

Event Date
Ransomware deployed on bank systems June 16, 2025
First SEC 8-K disclosure filed June 25, 2025
Deletion "representation" obtained from hackers Before July 30, 2025
Most recent SEC filing reviewed July 30, 2025
Lawsuits filed against the company At least 4 (as of filing)

As first reported by SecurityWeek, River hasn't disclosed which criminal group carried out the attack or how they initially broke in. The bank also said it hasn't yet determined whether the incident will materially affect its business or finances, a specific threshold under SEC cybersecurity disclosure rules finalized in 2023 that triggers mandatory public reporting. That determination, when it comes, will matter: it's the moment the bank must either confirm the damage or explain why it doesn't meet the bar.

© 2026 Threat Vectr