
River Financial Corporation
US bank holding company whose ransomware intrusion has drawn five SEC filings, materiality still undetermined.
River Financial Corporation, an Alabama bank holding company, filed a fifth SEC disclosure on 30 July 2026 over a June ransomware intrusion whose materiality remains undetermined six weeks on.
Last refreshed: 3 August 2026 · Appears in 1 active topic
Why did a small Alabama bank disclose a ransomware breach before knowing its scope?
Timeline for River Financial Corporation
Filed a fifth disclosure still unable to confirm materiality or PII exposure
Cybersecurity: Threats and Defences: A fifth filing, materiality still openFiled its fourth 8-K/A stating materiality remains undetermined
Cybersecurity: Threats and Defences: River stalls on breach materiality againFiled an SEC Item 1.05 material 8-K disclosing a ransomware intrusion
Cybersecurity: Threats and Defences: Alabama bank files a live-breach 8-KBackground
River Financial Corporation is a bank holding company based in Alabama, parent to a small regional bank. It came to notice through a ransomware intrusion into its systems in June 2026 and the sequence of regulatory filings that followed.
As a US public company, River Financial is subject to SEC rules requiring disclosure of cybersecurity incidents determined to be material; the extended run of filings without a materiality determination is itself the notable feature of its regulatory record so FAR.
River Financial operates at a smaller scale than the money-centre banks that typically dominate cybersecurity headlines, which makes its case a useful marker for how regulators expect community and regional banks to handle disclosure obligations when facing sophisticated ransomware actors with more limited in-house security resources than a larger institution would have.
River still cannot confirm materiality
River Financial Corporation first disclosed a ransomware attack to the SEC on 25 June 2026, after an intrusion that reached its systems around 16 June and was caught three days later. A fourth filing on 17 July again said the company could not yet determine whether the incident was material or how much customer data had been exposed.
A fifth disclosure, an amended Form 8-K, followed on 30 July, more than six weeks after the intrusion, with materiality and the scope of any personal data taken still open. Part of that assessment rests on representations from the attacker itself that the exfiltrated data was deleted.