US bank places trust in ransomware crew that promised to delete its data
History suggests this was not wise
River Financial Corporation's confidence in a ransomware group to erase stolen data has raised eyebrows among regulators. Over a month into the cleanup process, the bank disclosed to authorities that it had taken steps to attempt to remove the affected data, citing assurances from the threat actor regarding data deletion. However, this approach has been deemed unwise in the past, as evidenced by the 2024 takedown of LockBit, where evidence showed that victim data was retained even after ransom payments.
The bank has not confirmed whether it paid the ransom, a common practice among cybercriminals. River Bank initially informed the Securities and Exchange Commission (SEC) on June 16 about the ransomware attack, leading to the immediate isolation of infected systems and deployment of external forensic experts to assess the damage.
A day later, they acknowledged potential data impact, followed by confirmation by July 10. Despite these developments, the bank has not fully investigated the attack and has thus far not disclosed the complete extent of the incident.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.