FEDERALItem 1.05 · mandatoryHackingData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIILowActive
RIVER FINANCIAL CORPORATION
bd_5003c9d941db0a9c · schema v1 · pii pii-v1
River Financial Corporation filed a supplemental 8-K regarding a cybersecurity incident. An unauthorized threat actor accessed portions of its network and removed certain data. The nature and scope of the information, including PII, is still being determined. No fraud has been reported. Two class action lawsuits have been filed. The full impact has not yet been determined.
SEC clockMateriality determined Jun 19, 2026 → Filed Jul 10, 202621d ✗ SEC 4-day late21 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_712200f8a5f0b33aSEC 8-Kfiled 2026-07-06(4d gap)Verified by operator
- bd_994819586d228b3bSEC 8-Kfiled 2026-07-17(7d gap)Verified by operator
- bd_b49f2a1e760cb3eaSEC 8-Kfiled 2026-06-25(15d gap)Candidate
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1641601/000119312526300763/ck0001641601-20260619.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jul 10, 2026
- Raw hash
- fce9ad5679b65d0acf3abc5a5e462ca98d1ac50c86f56d71f58cd0869b84341b
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- River Financial Corporationnorm: river financial
- SEC CIK
- 0001641601
Victim entity
- Name
- RIVER FINANCIAL CORPORATIONnorm: river financial
- SEC CIK
- 0001641601
Incident
- Discovered
- Jun 19, 2026
- Materiality determined
- Jun 19, 2026
- Notification sent
- Jul 10, 2026
- Affected individuals
- Not disclosed
- Data types
- PII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 21 days(21 days from discovery to filing)
- Compliance flags
- SEC 4-day late · 21d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Jun 19, 2026→ Filed: Jul 10, 202621d cal. 4 business days SEC 4-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.