Overview
River Bank & Trust, an Alabama-based community bank with 25 locations across the state and one in Destin, Florida, has disclosed that threat actors stole data during a ransomware attack in June 2026 — and subsequently claimed to have deleted it. The bank says it "obtained representations from the threat actor" that the data was destroyed, a claim security researchers describe as unverifiable and almost certainly tied to a ransom payment the bank has declined to confirm.
The incident is a case study in a growing trend: ransomware groups using data deletion promises as a negotiating tool, even as documented evidence shows these promises are routinely broken.
The Attack
River Financial Corporation (RVRF), the holding company for River Bank & Trust, disclosed the incident via a Form 8-K filing with the SEC on June 25, 2026 — six days after the attack was discovered.
Timeline
| Date | Event |
|---|---|
| June 16, 2026 | Unauthorized threat actor gains access to the corporate network |
| June 19, 2026 | Bank discovers the intrusion and ransomware deployment |
| June 25, 2026 | Form 8-K filed with SEC; incident disclosed publicly |
| July 6–10, 2026 | Bank confirms data was "removed" from its environment |
| July 2026 | Bank announces hackers "confirmed" they deleted the stolen data |
| August 2026 | Investigation ongoing; class action lawsuits filed |
The Data Deletion Claim
River Financial stated in regulatory disclosures that it "took steps to attempt to suppress the affected data, including obtaining representations from the threat actor that it deleted the data in its possession."
The bank said it believes customers are unlikely to face harm as a result.
The bank did not confirm whether it paid a ransom. However, ransomware groups do not offer data deletion as a free service — the "deletion confirmation" is almost universally part of a ransom payment agreement.
What We Don't Know
- The identity of the ransomware group (unnamed in all filings)
- Whether a ransom was paid, and how much
- Which specific categories of customer data were stolen
- The total number of affected individuals
Why Security Experts Are Skeptical
The security community is unanimous: data deletion guarantees from ransomware groups offer no real protection.
When law enforcement dismantled LockBit in 2024, investigators discovered that victim data was retained in LockBit's systems even in cases where the ransom had been paid and victims were explicitly told their data had been deleted. The pattern has been observed across multiple other ransomware operations.
"Trusting a ransomware gang's promise to delete your data is like trusting a burglar's promise not to copy your house key — you have no way to verify it, and every incentive exists for them to lie." — Common security industry consensus
Once data is exfiltrated, there is no technical mechanism to confirm deletion. Ransomware groups have both the means and the motive to retain stolen data for future use — as leverage for follow-on extortion, for sale on dark web markets, or as intelligence on the target organization.
Impact and Response
Bank Operations
Certain bank systems were taken offline following discovery of the attack. Some systems had not returned to full capacity as of the June 25 SEC disclosure. Amgen stated the incident did not affect manufacturing or financial reporting — River Financial similarly indicated no systemic operational failure.
Customer Notification
Customer notification letters had not been fully distributed as of early July 2026. The bank indicated it would notify affected individuals as the forensic scope is determined. No specific data categories (account numbers, Social Security numbers, etc.) have been officially confirmed as stolen.
Legal Action
Multiple law firms have launched class action investigations on behalf of River Bank & Trust customers:
- Cory Watson Attorneys
- Levi Korsinsky
- ClassAction.org
Customers are advised to monitor their accounts, review credit reports through the three major bureaus, and consider placing a credit freeze as a precautionary measure.
The Broader Pattern: Ransomware "Deletion Deals"
River Bank is not the first institution to accept a threat actor's deletion promise. This is an established ransomware negotiation tactic:
- Exfiltrate data during initial access phase
- Deploy ransomware to encrypt systems and create operational pressure
- Demand ransom in exchange for decryption key + "data deletion"
- Provide deletion "confirmation" upon payment — which victims cannot verify
- Retain a copy for potential follow-on extortion or resale
Security guidance from the FBI, CISA, and NCSC consistently advises organizations not to pay ransoms — in part because payment does not reliably prevent data exposure, and paying funds future attacks.
What Customers Should Do
- Monitor bank accounts closely for unauthorized transactions
- Request a free credit report from all three bureaus (Equifax, Experian, TransUnion) at AnnualCreditReport.com
- Consider a credit freeze — this is free and prevents new accounts from being opened in your name
- Watch for phishing attempts — attackers with your bank account details may craft targeted email or phone scams
- Enable transaction alerts on all accounts so you're immediately notified of activity
- Do not assume data deletion is real — monitor your exposure on breach notification services regardless of the bank's assurances
Sources
- SecurityWeek — River Bank Says Hackers Deleted Data Stolen in Ransomware Attack
- The Register — US bank places trust in ransomware crew that promised to delete its data
- WSFA — River Bank & Trust investigating cyberattack
- SEC EDGAR — River Financial 8-K (June 25, 2026)
- ClassAction.org — River Bank & Trust Data Breach Lawsuit Investigation