A Bank's Bet on Criminal Honesty
When it comes to ransomware, one of the strangest parts of the entire criminal business model is the promise that follows payment: hand over the money, and we will delete your stolen data. River Financial Corporation, the parent company of Alabama-based River Bank & Trust, appears to have taken that promise at face value. In a Form 8-K filing with the Securities and Exchange Commission, the bank disclosed that it "took steps to attempt to suppress the affected data, including obtaining representations" from the attackers, essentially a written assurance that the stolen information would be destroyed. Notably, the filing does not explicitly confirm whether River Bank actually paid a ransom, even though obtaining such "representations" from ransomware operators typically only happens after money changes hands.
This disclosure lands at an awkward moment for anyone inclined to trust a ransomware data deletion promise. Law enforcement's takedown of the LockBit ransomware operation revealed that victim data was retained by the group's infrastructure even in cases where victims had already paid the extortion demand. In other words, the checkbox labeled "data deleted" that so many companies rely on to close the incident and reassure regulators, customers, and their own boards was, in at least some documented cases, simply false.
Why a Ransomware Data Deletion Promise Rarely Holds Up
The entire concept of paying a ransomware gang for data deletion rests on an obvious contradiction: you are asking a criminal organization, one that broke into your network and stole sensitive records in the first place, to voluntarily give up leverage. There is no enforcement mechanism, no audit trail, and no legal recourse if the group keeps a copy, sells it on a dark web marketplace, or uses it for a second round of extortion later. Security researchers have long warned that "proof of deletion" videos, screenshots, or written statements provided by ransomware crews are unverifiable by design. The LockBit takedown simply put hard evidence behind what many in the security community had already assumed.
For a financial institution, this matters enormously. Banks hold some of the most sensitive personal data that exists, including Social Security numbers, account details, and transaction histories. When that data is exfiltrated during an intrusion, a criminal's promise to delete it offers no actual protection to the customers whose information was exposed. It offers, at best, a talking point for a regulatory filing.
How the Breach Happened
River Bank's incident did not occur in a vacuum. According to earlier threat intelligence reporting, the breach was tied to an unauthorized actor gaining access through an aging VPN protocol vulnerability, a detail explored in our earlier coverage of the River Bank & Trust ransomware incident. Outdated remote access infrastructure remains one of the most common entry points for ransomware crews, precisely because it often sits at the edge of a network, is easy to scan for, and is frequently overlooked in patch management cycles. Once inside, attackers typically move laterally, locate valuable data stores, and exfiltrate information before ever triggering a ransomware payload, meaning the theft often happens well before anyone notices anything is wrong.
What This Means For You
If you are a River Bank & Trust customer, or a customer of any institution that has disclosed a ransomware incident, the practical reality is this: any promise from the attackers to delete your data should not be treated as a guarantee of safety. Once information leaves a company's network in a ransomware attack, it should be treated as permanently compromised, regardless of what assurances are later obtained. That means monitoring your accounts and credit reports for unusual activity, being alert to phishing attempts that reference real account details (a common follow-up tactic when stolen banking data circulates among criminal groups), and considering a credit freeze if Social Security numbers or account numbers were part of the exposed data set.
For businesses and financial institutions watching this story unfold, the lesson is broader. Relying on a ransomware data deletion promise as part of an incident response strategy, let alone as something worth disclosing to regulators as a mitigating step, sends the wrong signal about how seriously an organization is treating data protection. Verified backups, network segmentation, and prompt patching of remote access infrastructure like VPN gateways do far more to protect customer data than any assurance extracted from a criminal enterprise ever could.
Takeaways
- Treat any ransomware group's promise to delete stolen data as unverifiable and unenforceable, not a genuine safeguard.
- If you bank with an institution that has disclosed a breach, monitor statements and credit reports closely and consider a credit freeze.
- Be extra cautious of phishing messages that reference accurate account or personal details in the weeks and months following a disclosed incident.
- Organizations should prioritize patching known VPN and remote access vulnerabilities, since outdated protocols remain a leading entry point for ransomware crews.
As ransomware investigations continue to expose the gap between what criminal groups promise and what they actually do, both consumers and companies should plan as though stolen data is never truly gone, no matter what representation a ransomware crew provides in writing.




