US bank places trust in ransomware crew that promised to delete its data

chrisjj1 pts0 comments

US bank places trust in ransomware crew that promised to delete its data

Jump to main content

Search

REG AD

Cyber-crime

US bank places trust in ransomware crew that promised to delete its data

History suggests this was not wise

Connor Jones

Connor<br>Jones

Cybersecurity reporter

Published<br>fri 31 Jul 2026 // 16:41 UTC

Would you trust a ransomware extortionist to delete the data they stole? One bank certainly wants you to. Well over a month into a ransomware cleanup job, River Financial Corporation tells regulators that it “took steps to attempt to suppress the affected data, including obtaining representations from the threat actor that it deleted the data in its possession.”<br>For context, placing this kind of trust in this kind of individual has been proven to be a bad idea. When globo-cops took down LockBit in 2024, they found evidence that victim data was retained even after the victim had paid the extortion demands.<br>In its Form 8-K filing with the SEC, River Bank did not explicitly state whether or not it paid any of the criminals’ ransom demands, although ransomware crooks are not commonly known to offer a victim data deletion for free.

REG AD

The Register asked the company for a more explicit comment on this matter, but it did not immediately respond.

REG AD

River Bank first disclosed its cyber woes to the Securities and Exchange Commission (SEC) on June 16, admitting from the outset that ransomware had been deployed across portions of its servers.

MORE CONTEXT

Greedy ransomware crews return for seconds after victims cough up first extortion payments

Charities remain locked out of CAF Bank online accounts

Confused by the SEC's IT security breach reporting rules? Read this

US chip testing firm shrugged off ransomware hit as minor – then came the data leak

In response, it took affected systems offline, disabled admin accounts, and brought in external incident responders to determine the full scope of the damage.<br>Only July 6, messaging suggested it was aware that some data was “potentially impacted” by the attack, before admitting that certain data was removed from its environment four days later.

A side note on cyber verbiage

“Removed” is an interesting and unusual word to see in a disclosure when describing what an intruder did with their access.<br>The usual nomenclature is “stolen,” despite in most cases it being more accurate to say data was “copied” from a victim’s environment.<br>Some of the more nebulous announcements say data was “acquired” or “retrieved.” Sometimes “affected.”<br>The more cowardly ones simply stick with “accessed,” even though the word does not denote a change of ownership.

By July 10, River was aware the data had been removed, and two class action lawsuits had been filed against it, to top things off.<br>A week later, it told investors that an additional two class actions had been filed, bringing the total to four.<br>River has not yet completed its investigation, per its most recent filing, and therefore has not confirmed the full scope or impact of the attack. ®

cyber-crime<br>ransomware

REG AD

OFFBEAT

Meet the 'internet radical' who helped Microsoft get email and AT&T get online

Tom Evslin on Bill Gates, the birth of Exchange, and dragging Ma Bell onto the web

Unexpected item in the bagging area as Windows Activation error pops up at check-in

Bags weighed down by a Microsoft license key

From individual achievement to partner impact

PARTNER CONTENT: Databricks survey data suggests certified professionals lift partner delivery capacity, customer credibility, and AI readiness well beyond the individuals who earn the credential

SYSTEMS

A deep dive into Nvidia's Vera CPU and the Olympus cores that power it

88 custom cores, 176 funky threads, 1.5 TB of laptop RAM, and 1.8 TB/s of NVLink connectivity — this isn't your typical datacenter chip

PAAS AND IAAS

Amazon's Q2 was great, but the earnings release is packed with baloney

"Tell me lies, tell me sweet little lies"

OFF-PREM

Enterprise cloud infrastructure uptake shows no sign of slowing

Cloud revenue now north of $143 billion a quarter, and growth is accelerating

MOST POPULAR

software

Techie lured out of retirement to support software only he remembered

NETWORKS

Three becomes one as Vodafone buys out merger partner

security

Word worm crawls into Copilot, spreads chaos

DEVOPS

Dev who gave HashiCorp its name returns with a faster terminal multiplexer

DATABASES

After rewriting SQLite in Rust, Turso turns its sights on Postgres

AI

SYSTEMS

A deep dive into Nvidia's Vera CPU and the Olympus cores that power it

88 custom cores, 176 funky threads, 1.5 TB of laptop RAM, and 1.8 TB/s of NVLink connectivity — this isn't your typical datacenter chip

OFF-PREM

Enterprise cloud infrastructure uptake shows no sign of slowing

Cloud revenue now north of $143 billion a quarter, and growth is accelerating

DEVOPS

Dev who gave HashiCorp its name returns with a faster terminal multiplexer

Persistent sessions...

data ransomware bank trust river from

Related Articles