River Bank Paid Ransomware Crew to Delete Stolen Data. Trust Them on That.
River Financial Corporation, the holding company for Alabama-based River Bank & Trust, is telling regulators that hackers who raided its systems have deleted the stolen data. Whether you believe that is another matter entirely.
The attack hit on June 16. Staff noticed something was wrong three days later. By then, ransomware had already spread across parts of the bank's server infrastructure. River pulled affected systems offline and killed compromised admin accounts, which is the right move, though by definition it comes after the damage is done.
The company filed an 8-K with the SEC on June 25 confirming the breach and flagging that personal data may have been accessed or taken. Further filings added detail: yes, the attackers got into portions of the network, yes, they exfiltrated data, and yes, at least four lawsuits have already landed on River's doorstep.
A July 30 filing is where things get interesting. River still cannot confirm whether any personal information was actually stolen. But buried in the regulatory language is a fairly clear signal that money changed hands.
"River took steps to attempt to suppress the affected data, including obtaining representations from the threat actor that it deleted the data in its possession," the company wrote.
Translation: they paid up, or reached some kind of agreement, and got a pinky promise back that the data is gone. In ransomware circles, those promises are worth precisely nothing. Threat actors routinely retain copies regardless of what they tell victims, and there is no independent way to verify deletion ever happened.
River has not named the group behind the attack, disclosed how they got in, or confirmed whether the incident will have any material impact on its finances. Which, given four active lawsuits and a ransomware payload loose in your servers, seems optimistic.
We will update this if River says anything more illuminating than "we paid them and they said they deleted it, honest."