Securityaffairs.Co River Financial Corporation Confirms Data Deletion by Ransomware Attackers
Article Content
- •River Financial Corporation experienced a ransomware attack starting June 16, 2026.
- •The company received assurances from attackers that stolen data was deleted.
- •At least four lawsuits have been filed against River Financial due to the incident.
River Financial Corporation reported that hackers deleted data stolen during a ransomware attack that began on June 16, 2026. The company detected the intrusion three days later and took immediate containment measures, including disabling compromised accounts and taking affected systems offline. They are currently working with a third-party forensic firm to assess the full scope of the breach. Despite assurances from the attackers regarding data deletion, River has not confirmed whether any personally identifiable information was accessed. The company has faced at least four lawsuits related to the incident and continues to investigate the potential impact on its business. River has not disclosed the identity of the threat actor or the method of compromise used in the attack.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Lockbit and River Bank in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…