FEDERALItem 1.05 · mandatoryMalwareRansomwareData EncryptedMulti-Stage ChainPIILowActive
River Financial Corporation
bd_b49f2a1e760cb3ea · schema v1 · pii pii-v1
Full breach record for River Financial Corporation →River Financial Corporation (including River Bank & Trust) filed an 8-K disclosing a material cybersecurity incident. On or about June 16, 2026, an unauthorized threat actor gained access to the network, deploying ransomware across portions of the server environment. River identified the activity on June 19, 2026, and took containment measures, including disabling accounts and taking systems offline. The investigation into the scope and whether PII was exfiltrated is ongoing.
SEC clockMateriality determined Jun 19, 2026 → Filed Jun 25, 20266d ✓ SEC 4-day OK6 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_712200f8a5f0b33aSEC 8-Kfiled 2026-07-06(11d gap)Verified by operator
- bd_5003c9d941db0a9cSEC 8-Kfiled 2026-07-10(15d gap)Verified by operator
- bd_994819586d228b3bSEC 8-Kfiled 2026-07-17(22d gap)Verified by operator
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1641601/000119312526282946/ck0001641601-20260619.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jun 25, 2026
- Raw hash
- 3de75579c2afd254cade8609beedc876f77c087c9a7560862af8aa3ac2157e95
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- River Financial Corporationnorm: river financial
- SEC CIK
- 0001641601
Victim entity
- Name
- River Financial Corporationnorm: river financial
Incident
- Discovered
- Jun 19, 2026
- Materiality determined
- Jun 19, 2026
- Notification sent
- Jun 25, 2026
- Affected individuals
- Not disclosed
- Data types
- PII
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 6 days(6 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 6d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Jun 19, 2026→ Filed: Jun 25, 20266d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.