River Financial Corporation filed a supplemental 8-K (Item 1.05) regarding a cybersecurity incident. The company determined an unauthorized threat actor accessed its network and exfiltrated data. The full scope and nature of the information (including PII) are undetermined. River attempted to suppress data by obtaining representations from the threat actor that it deleted the data. The incident is ongoing and materiality is not yet determined.