Breach taxonomy
Summary
An unauthorized threat actor gained access to the network environment of River Financial Corporation, including River Bank & Trust, on or about June 16, 2026. River identified the activity on June 19 and determined ransomware had been deployed across portions of its server environment; impacted systems were taken offline and certain operations were disrupted. A July 30, 2026 amendment confirmed the actor removed data from River's environment, and that River sought to suppress the stolen data by obtaining representations from the threat actor that it had deleted its copy. Whether personally identifiable information was affected remained under investigation, and materiality had not yet been determined.
Tagging rationale
ThreatUnknown
Filing refers only to 'an unauthorized threat actor' with no attribution -> UNKNOWN.
MethodsRansomwareData Exfil
Original filing states ransomware 'had been deployed across portions of its server environment' -> RANSOMWARE; the 7/30/2026 8-K/A confirms the actor 'accessed portions of its network and removed certain data from its environment' -> DATA-EXFIL added.
AssetsRevenue Process
Ransomware was deployed 'across portions of its server environment' at a bank and 'certain operations have been impacted' -> REVENUE-PROCESS; PII exposure not yet confirmed.
EffectsBiz InterruptionCyber Extortion
Systems were taken offline and 'certain operations have been impacted' -> BIZ-INTERRUPTION; the amendment states River obtained 'representations from the threat actor that it deleted the data in its possession', indicating direct engagement with the actor over stolen data -> CYBER-EXTORTION added.
Business continuityPartial
Impacted systems were taken offline and 'certain operations have been impacted, but River is working with external cybersecurity professionals to fully restore these operations' -> Partial.
Impact
Ransomware across a community bank's server environment with operational disruption, and a later amendment confirming data theft and negotiation with the actor, but no disclosed record count, ransom amount, or financial impact -> score 3.
InsuranceNot disclosed
Filing makes no mention of insurance -> null.
Read the original SEC filing excerpt
On or about June 16, 2026, an unauthorized threat actor gained access to the network environment of River Financial Corporation, including River Bank & Trust (together, "River"). River identified the activity on or about June 19, 2026, and determined that ransomware had been deployed across portions of its server environment. River promptly took containment measures, including disabling affected administrative accounts and taking impacted systems offline. River, with the assistance of a third-party forensic firm, is investigating the nature and scope of the incident, including whether any personally identifiable information was subject to unauthorized access or exfiltration. That investigation is ongoing. As of the date of this filing, the full nature, scope, and impact of the incident have not yet been determined. River has not yet determined whether the incident is reasonably likely to materially impact its business or financial condition. Certain operations have been impacted, but River is working with external cybersecurity professionals to fully restore these operations. River will file an amendment to this Current Report on Form 8-K within four business days after it determines that such information is available. [8-K/A filed 2026-07-30] ITEM 1.05 Material Cybersecurity Incidents. Since the date of the original filing, River's investigation has progressed. River has determined that an unauthorized threat actor accessed portions of its network and removed certain data from its environment. River is working to determine the nature and scope of the information involved, including whether any personally identifiable information was affected. As part of its response, River took steps to attempt to suppress the affected data, including obtaining representations from the threat actor that it deleted the data in its possession. As of the date of this filing, the full nature, scope, and impact of the incident have not yet been determined. River has not yet confirmed whether the incident is reasonably likely to materially impact its business or financial condition. River will file an amendment to this Current Report on Form 8-K within four business days after it determines that such information is available.