Contained High impact Ransomware Checked 6h ago

Ransomware hits Alabama bank River Bank and Trust

River Financial Corporation, the parent of River Bank & Trust, says an intruder entered its network in mid-June and deployed ransomware on part of its servers. The attacker later claimed that the stolen data was deleted. The investigation into whether personal data was accessed or stolen remained open as of August 4, 2026. No newer credible update was found.

Started
Jun 16, 2026
Latest activity
Aug 4, 2026
Attributed to
Not confirmedNo credible attribution yet
Where
United States
Sectors
Finance
Scale
One regional bank holding company, with 24 full-service banking offices in Alabama and one in Destin, Florida.

Current status

No credible update dated after August 4, 2026 was found; the investigation remains the latest reported state.

Contained: The attack has been stopped or blocked. Recovery and investigation are still running.

Impact

Ransomware affected part of River Bank & Trust's server environment and disrupted some operations. The company has not publicly identified the affected customer services or confirmed that personal data was exposed. Four class action complaints seek damages related to the incident.

What to do

Customers should watch for a breach notification, review bank and credit accounts for unusual activity, and report suspicious transactions promptly.

Timeline

  1. Aug 4, 2026

    River Financial said its investigation remained open and disclosed that four class action complaints had been filed in Alabama state courts in July over the incident.

    Containedsec.gov
  2. Aug 3, 2026

    The bank said it received assurances from the attackers that the stolen data was deleted, while its investigation with a third-party forensic firm continued.

    Containedsecurityweek.com
  3. Aug 3, 2026

    River said it obtained representations from the attacker that the stolen data had been deleted, while the investigation into scope and impact continues.

    Containedsecurityweek.com
  4. Aug 3, 2026

    River Financial said it received confirmation from the attackers that the stolen data was deleted, though the investigation is still ongoing.

    Containedsecurityweek.com
  5. Jul 17, 2026

    River Financial Corporation filed an SEC Form 8-K disclosing the cybersecurity incident.

    Activewsfa.com
  6. Jun 25, 2026

    River Financial disclosed the ransomware attack in a Form 8-K filed with the SEC.

    Activedysruptionhub.com
  7. Jun 19, 2026

    River Financial Corporation discovered ransomware had been deployed on affected systems, three days after initial access.

    Activesecurityaffairs.com
  8. Jun 19, 2026

    River identified the activity and determined ransomware had been deployed across portions of its server environment, then disabled affected accounts and took systems offline.

    Activesecurityaffairs.com
  9. Jun 19, 2026

    River Financial identified the intrusion and determined ransomware had been deployed across parts of its server environment, then took affected systems offline.

    Activedysruptionhub.com
  10. Jun 16, 2026

    An unauthorized threat actor gained access to River Bank & Trust's network environment.

    Emerging1819news.com
  11. Jun 16, 2026

    An unauthorized threat actor gained access to River Financial Corporation's network environment.

    Emergingsecurityaffairs.com
  12. Jun 16, 2026

    An unauthorized actor gained access to River Financial Corporation's network, including River Bank and Trust, according to the company's SEC filing.

    Emergingdysruptionhub.com

Sources

Related reports