Security News

River Bank Confirms Hackers Deleted Data Stolen in June Ransomware Attack

Security Week · 3 Aug 2026
Key Takeaway Australian small businesses should assume that any data stolen in a ransomware attack could be misused, even if attackers claim otherwise, and should focus on strong backups and access controls to prevent breaches in the first place.

River Bank, a bank holding company, has revealed that it was targeted in a ransomware attack back in June. The organisation has since confirmed that the hackers responsible for stealing data during the incident have deleted the stolen information, though details on how this was verified have not been disclosed.

Despite this development, the investigation into the breach is continuing, meaning the full scope of the incident—including what data was accessed, how many customers may be affected, and how the attackers gained entry—remains unclear. Ransomware attacks against financial institutions remain a serious concern, as banks and similar organisations hold sensitive customer and financial data that can be highly valuable to cybercriminals.

This case highlights an ongoing trend where attackers not only encrypt systems but also steal data beforehand, using the threat of exposure as additional leverage—commonly known as double extortion. Even when attackers claim to have deleted stolen data, businesses and customers are often advised to remain cautious, as such claims cannot always be independently verified.

Regulated in financial services? APRA CPS 220, 230 and 234, in plain language ->

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.