US bank places trust in ransomware crew that promised to delete its data

6 hours ago 7

Cyber-crime

History suggests this was not wise

Would you trust a ransomware extortionist to delete the data they stole? One bank certainly wants you to. Well over a month into a ransomware cleanup job, River Financial Corporation tells regulators that it “took steps to attempt to suppress the affected data, including obtaining representations from the threat actor that it deleted the data in its possession.”

For context, placing this kind of trust in this kind of individual has been proven to be a bad idea. When globo-cops took down LockBit in 2024, they found evidence that victim data was retained even after the victim had paid the extortion demands.

In its Form 8-K filing with the SEC, River Bank did not explicitly state whether or not it paid any of the criminals’ ransom demands, although ransomware crooks are not commonly known to offer a victim data deletion for free.

The Register asked the company for a more explicit comment on this matter, but it did not immediately respond.

River Bank first disclosed its cyber woes to the Securities and Exchange Commission (SEC) on June 16, admitting from the outset that ransomware had been deployed across portions of its servers.

In response, it took affected systems offline, disabled admin accounts, and brought in external incident responders to determine the full scope of the damage.

Only July 6, messaging suggested it was aware that some data was “potentially impacted” by the attack, before admitting that certain data was removed from its environment four days later.

A side note on cyber verbiage

“Removed” is an interesting and unusual word to see in a disclosure when describing what an intruder did with their access. 

The usual nomenclature is “stolen,” despite in most cases it being more accurate to say data was “copied” from a victim’s environment.

Some of the more nebulous announcements say data was “acquired” or “retrieved.” Sometimes “affected.”

The more cowardly ones simply stick with “accessed,” even though the word does not denote a change of ownership.

By July 10, River was aware the data had been removed, and two class action lawsuits had been filed against it, to top things off.

A week later, it told investors that an additional two class actions had been filed, bringing the total to four.

River has not yet completed its investigation, per its most recent filing, and therefore has not confirmed the full scope or impact of the attack. ®

Read Entire Article