Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2188+ Articles
157+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. River Bank Says Hackers Deleted Data Stolen in Ransomware Attack
River Bank Says Hackers Deleted Data Stolen in Ransomware Attack
NEWS

River Bank Says Hackers Deleted Data Stolen in Ransomware Attack

River Bank & Trust in Alabama says it obtained representations from the ransomware group that attacked it in June 2026 that the stolen data has been deleted — a claim security experts say is unverifiable and likely tied to a ransom payment.

Dylan H.

News Desk

August 3, 2026
5 min read

Overview

River Bank & Trust, an Alabama-based community bank with 25 locations across the state and one in Destin, Florida, has disclosed that threat actors stole data during a ransomware attack in June 2026 — and subsequently claimed to have deleted it. The bank says it "obtained representations from the threat actor" that the data was destroyed, a claim security researchers describe as unverifiable and almost certainly tied to a ransom payment the bank has declined to confirm.

The incident is a case study in a growing trend: ransomware groups using data deletion promises as a negotiating tool, even as documented evidence shows these promises are routinely broken.


The Attack

River Financial Corporation (RVRF), the holding company for River Bank & Trust, disclosed the incident via a Form 8-K filing with the SEC on June 25, 2026 — six days after the attack was discovered.

Timeline

DateEvent
June 16, 2026Unauthorized threat actor gains access to the corporate network
June 19, 2026Bank discovers the intrusion and ransomware deployment
June 25, 2026Form 8-K filed with SEC; incident disclosed publicly
July 6–10, 2026Bank confirms data was "removed" from its environment
July 2026Bank announces hackers "confirmed" they deleted the stolen data
August 2026Investigation ongoing; class action lawsuits filed

The Data Deletion Claim

River Financial stated in regulatory disclosures that it "took steps to attempt to suppress the affected data, including obtaining representations from the threat actor that it deleted the data in its possession."

The bank said it believes customers are unlikely to face harm as a result.

The bank did not confirm whether it paid a ransom. However, ransomware groups do not offer data deletion as a free service — the "deletion confirmation" is almost universally part of a ransom payment agreement.

What We Don't Know

  • The identity of the ransomware group (unnamed in all filings)
  • Whether a ransom was paid, and how much
  • Which specific categories of customer data were stolen
  • The total number of affected individuals

Why Security Experts Are Skeptical

The security community is unanimous: data deletion guarantees from ransomware groups offer no real protection.

When law enforcement dismantled LockBit in 2024, investigators discovered that victim data was retained in LockBit's systems even in cases where the ransom had been paid and victims were explicitly told their data had been deleted. The pattern has been observed across multiple other ransomware operations.

"Trusting a ransomware gang's promise to delete your data is like trusting a burglar's promise not to copy your house key — you have no way to verify it, and every incentive exists for them to lie." — Common security industry consensus

Once data is exfiltrated, there is no technical mechanism to confirm deletion. Ransomware groups have both the means and the motive to retain stolen data for future use — as leverage for follow-on extortion, for sale on dark web markets, or as intelligence on the target organization.


Impact and Response

Bank Operations

Certain bank systems were taken offline following discovery of the attack. Some systems had not returned to full capacity as of the June 25 SEC disclosure. Amgen stated the incident did not affect manufacturing or financial reporting — River Financial similarly indicated no systemic operational failure.

Customer Notification

Customer notification letters had not been fully distributed as of early July 2026. The bank indicated it would notify affected individuals as the forensic scope is determined. No specific data categories (account numbers, Social Security numbers, etc.) have been officially confirmed as stolen.

Legal Action

Multiple law firms have launched class action investigations on behalf of River Bank & Trust customers:

  • Cory Watson Attorneys
  • Levi Korsinsky
  • ClassAction.org

Customers are advised to monitor their accounts, review credit reports through the three major bureaus, and consider placing a credit freeze as a precautionary measure.


The Broader Pattern: Ransomware "Deletion Deals"

River Bank is not the first institution to accept a threat actor's deletion promise. This is an established ransomware negotiation tactic:

  1. Exfiltrate data during initial access phase
  2. Deploy ransomware to encrypt systems and create operational pressure
  3. Demand ransom in exchange for decryption key + "data deletion"
  4. Provide deletion "confirmation" upon payment — which victims cannot verify
  5. Retain a copy for potential follow-on extortion or resale

Security guidance from the FBI, CISA, and NCSC consistently advises organizations not to pay ransoms — in part because payment does not reliably prevent data exposure, and paying funds future attacks.


What Customers Should Do

  1. Monitor bank accounts closely for unauthorized transactions
  2. Request a free credit report from all three bureaus (Equifax, Experian, TransUnion) at AnnualCreditReport.com
  3. Consider a credit freeze — this is free and prevents new accounts from being opened in your name
  4. Watch for phishing attempts — attackers with your bank account details may craft targeted email or phone scams
  5. Enable transaction alerts on all accounts so you're immediately notified of activity
  6. Do not assume data deletion is real — monitor your exposure on breach notification services regardless of the bank's assurances

Sources

  • SecurityWeek — River Bank Says Hackers Deleted Data Stolen in Ransomware Attack
  • The Register — US bank places trust in ransomware crew that promised to delete its data
  • WSFA — River Bank & Trust investigating cyberattack
  • SEC EDGAR — River Financial 8-K (June 25, 2026)
  • ClassAction.org — River Bank & Trust Data Breach Lawsuit Investigation

Related Reading

  • Amgen Patient Data Stolen From Third-Party Cloud Systems
  • PNLD Breach Exposes UK Police and Government Contact Details
#Ransomware#Banking#Cybercrime#SEC Disclosure#Incident Response

Related Articles

Coca-Cola Fairlife Ransomware Attack Halts All US Dairy Production

The Coca-Cola Company filed an SEC 8-K disclosure after a ransomware attack on its Fairlife dairy subsidiary temporarily suspended all US production of...

3 min read

New Spirals Ransomware Encrypts Victim Network in Under 24 Hours

A newly identified ransomware group called Spirals has demonstrated alarming operational speed, completing the full attack lifecycle — initial access,...

4 min read

New Prinz Eugen Ransomware Prioritizes Recent Files for Encryption

A new Go-based ransomware operation named Prinz Eugen targets recently modified files first, uses ChaCha20-Poly1305 encryption, and communicates with...

3 min read
Back to all News