River Financial Corporation, the parent company of River Bank & Trust, has confirmed that data compromised in a recent ransomware attack has been deleted. The financial institution disclosed this development after a thorough investigation into the incident, which initially occurred on June 16 and was identified on June 19.
Details of the Ransomware Attack
An internal review by River Bank revealed that parts of its server infrastructure were infiltrated by ransomware. In an immediate response, the company disconnected the affected systems and deactivated compromised administrative accounts to prevent further unauthorized access.
With assistance from a third-party forensic team, River Bank is delving into the extent and impact of the breach. A filing submitted to the US Securities and Exchange Commission (SEC) on June 25 highlighted ongoing efforts to ascertain whether any personal information was exposed or removed without authorization.
Legal Actions and Ongoing Investigations
Subsequent SEC disclosures revealed that the intruders gained access to sections of River’s network, extracting certain data. Consequently, the company faces at least four legal actions related to the breach. Despite these challenges, the investigation continues, with the bank yet to verify if any personal data was compromised, as per a filing dated July 30.
River Bank has engaged with the cybercriminals, aiming to ensure the deletion of stolen data, possibly through a ransom negotiation. The bank has not disclosed the identity of the hackers or the method used to breach their security infrastructure.
Future Implications and Response
As of now, River Bank has not determined whether the breach will have a significant impact on its business operations or fiscal health. The company remains tight-lipped about specific details regarding the perpetrators of the cyberattack.
SecurityWeek is actively seeking additional insights from River Bank regarding the ransomware incident and will provide updates as more information becomes available.
This incident aligns with a pattern of recent data breaches affecting major organizations, underscoring the critical need for robust cybersecurity measures.
