River Bank & Trust Confirms Deletion of Stolen Data Following Ransomware Attack
AI-generated from multiple sources. Verify before acting on this reporting.
NEW YORK — River Financial Corporation confirmed Monday that hackers responsible for a recent ransomware attack against its subsidiary, River Bank & Trust, have deleted the customer data they stole. The announcement marks a significant development in an incident where threat actors initially exfiltrated sensitive information before demanding payment.
The bank stated that following negotiations with the cybercriminal group, the attackers verified and executed the deletion of the compromised files from their servers. While River Bank & Trust did not disclose whether a ransom was paid to secure this outcome, the company's confirmation implies an engagement between the financial institution and the threat actors resulted in the data's removal.
The attack disrupted operations at the U.S.-based bank earlier this week, prompting immediate security protocols to isolate affected systems. Cybersecurity experts have long warned that modern ransomware campaigns often involve a dual-threat strategy: encrypting critical files while simultaneously stealing data to leverage against victims who refuse to pay or attempt recovery without paying.
River Financial Corporation emphasized that the deletion of the stolen material removes the risk of public exposure for its customers, including personal identification numbers and financial account details. The bank has since restored full functionality across all branches and digital platforms following a comprehensive system audit.
"We have received confirmation from the threat actors that the data is no longer in their possession," a company spokesperson said during a press briefing on Monday afternoon. "Our priority remains protecting our customers' privacy, and we are working closely with federal authorities to ensure this incident does not recur."
Despite the reported deletion of files, cybersecurity professionals caution that absolute certainty regarding data destruction by criminal groups is difficult to guarantee without independent verification from third-party auditors. There remain questions about whether copies of the stolen information were distributed before the attackers agreed to delete their primary cache.
Federal investigators are continuing their inquiry into the breach, examining the methods used by the hackers and tracing the financial transactions associated with the incident. River Bank & Trust has offered free credit monitoring services to all affected customers as a precautionary measure while law enforcement agencies work to identify the perpetrators behind the attack.
The incident underscores the evolving nature of cyber threats facing regional banks in 2026, where data exfiltration has become a standard component of ransomware demands. As River Financial Corporation moves toward full recovery, industry analysts are watching closely for any signs that the stolen information may resurface on underground markets despite the bank's assurances.