US bank places trust in ransomware crew that promised to delete its data
History suggests this was not wise
River Financial Corporation, a US bank, has placed its trust in a ransomware extortion crew, despite the well-documented risks associated with such a decision. Over a month into the cleanup process, the bank claimed to have taken steps to suppress the stolen data, including obtaining representations from the threat actor that they deleted the information they possessed.
However, this practice has proven to be problematic in the past. When law enforcement dismantled the LockBit ransomware group in 2024, they discovered that victim data was retained even after the victims had paid the extortion demands. River Bank did not explicitly state whether it paid any ransom, though it is not customary for cybercriminals to offer free data deletion.
The bank disclosed its cyber issues to the Securities and Exchange Commission on June 16, admitting from the start that ransomware had infiltrated certain portions of its servers. In response, River isolated the affected systems, disabled admin accounts, and enlisted external incident responders to assess the full extent of the damage.
By July 10, it confirmed that the data had been removed from its environment. Nevertheless, the bank has faced criticism, with two class action lawsuits filed against it in the aftermath. As of its most recent filing, River has not finalized its investigation and therefore cannot confirm the full scope or impact of the attack.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.