STOCK TITAN

River Financial Corporation (RVRF) details network data access by attacker

(Neutral)
(Neutral)
Form Type
8-K/A

Rhea-AI Filing Summary

River Financial Corporation reports that its ongoing investigation into a June 19, 2026 cybersecurity incident has determined that an unauthorized threat actor accessed portions of its network and removed certain data. The company is working to identify the nature and scope of the information involved, including whether any personally identifiable information was affected.

As part of its response, River obtained representations from the threat actor that the data in its possession was deleted and took steps to suppress the affected data. The full nature, scope, and impact of the incident, including whether it is reasonably likely to materially impact River’s business or financial condition, have not yet been determined. River plans to file another amendment within four business days after it determines that such information is available.

Positive

  • None.

Negative

  • None.
Item 1.05 Material Cybersecurity Incidents Business
A cybersecurity incident that the company has determined to be material to investors.
Item 9.01 Financial Statements and Exhibits Exhibits
Financial statements, pro forma financial information, and exhibit attachments filed with this report.
Date of earliest event June 19, 2026 Earliest date of the reported cybersecurity incident
Amendment timing four business days Planned timeframe to file another amendment after information becomes available
Filing signature date July 30, 2026 Date the report was signed by the Chief Executive Officer
Material Cybersecurity Incidents regulatory
"ITEM 1.05 Material Cybersecurity Incidents."
threat actor technical
"an unauthorized threat actor accessed portions of its network and removed certain data"
A threat actor is an individual, group, or organization that deliberately tries to harm a company’s systems, data, or operations—ranging from lone hackers and criminal gangs to insiders or state-sponsored teams. For investors this matters because successful attacks can cause direct financial loss, regulatory fines, interrupted business, or damaged trust—like a burglar stealing valuables or sabotaging a storefront, harming the company’s value and future earnings.
personally identifiable information technical
"including whether any personally identifiable information was affected"
Personally identifiable information (PII) is any data that can directly or indirectly identify a single person — for example: full name, home address, national ID numbers, phone or email, financial account details, or unique biometric data. Investors care because mishandling or loss of PII can trigger regulatory fines, costly cleanup and lost customer trust; think of a data breach like losing the keys to many customers’ homes, which can hurt a company’s finances and stock value.
emerging growth company regulatory
"Emerging growth company "
An emerging growth company is a recently public or smaller public firm that qualifies for temporary, lighter regulatory and disclosure rules to reduce the cost and effort of being public. For investors, it means the company may provide less historical financial detail and face fewer reporting requirements than larger firms, so it can grow more quickly but also carries higher uncertainty—like buying a promising early-stage product with fewer user reviews.

AI-generated analysis. How Rhea-AI works. Not financial advice.

See more from StockTitan in Google Search and AI answers. Adds StockTitan as a preferred source · opens Google
Add on Google
Learn about SEC filing dates

FAQ

What cybersecurity incident did River Financial Corporation (RVRF) disclose?

River Financial disclosed a cybersecurity incident in which an unauthorized threat actor accessed parts of its network and removed data. The company is still determining what information was involved and whether any personally identifiable information was affected.

Has personally identifiable information been compromised in the RVRF cyber incident?

River Financial has not yet determined whether personally identifiable information was involved in the incident. The company’s investigation is focused on defining the nature and scope of the affected data, including any potential impact on personal information.

How has River Financial Corporation (RVRF) responded to the cyberattack?

River Financial reports that it took steps to suppress the affected data, including obtaining representations from the threat actor that it deleted the data. The company continues investigating to assess the full nature, scope, and potential business or financial impact.

Is the cybersecurity incident expected to materially impact RVRF’s business or financial condition?

River Financial states it has not yet confirmed whether the incident is reasonably likely to materially impact its business or financial condition. That assessment depends on the ongoing investigation into the incident’s full nature, scope, and the information involved.

When will River Financial Corporation (RVRF) provide further updates on the cyber incident?

River Financial expects to file another amendment within four business days after it determines that additional information is available. That future amendment is intended to provide more detail on the incident’s scope and any confirmed business or financial impacts.
0001641601false00016416012026-06-192026-06-19

 

UNITED STATES

SECURITIES AND EXCHANGE COMMISSION

WASHINGTON, DC 20549

FORM 8-K

CURRENT REPORT

PURSUANT TO SECTION 13 OR 15(d)

OF THE SECURITIES EXCHANGE ACT OF 1934

Date of earliest event reported: June 19, 2026

RIVER FINANCIAL CORPORATION

(Exact Name of Registrant as Specified in its Charter)

 

Not Applicable

(Former Name or Former Address, if Changed Since Last Report)

 

Alabama

333-205986

46-1422125

(State or Other Jurisdiction

of Incorporation)

(Commission

File Number)

(IRS Employer

Identification No.)

2611 Legends Drive

Prattville, Alabama

36066

(Address of Principal Executive Offices)

(Zip Code)

(334) 290-1012

(Registrant’s telephone number, including area code)

Check the appropriate box below if the Form 8-K filing is intended to simultaneously satisfy the filing obligation of the registrant under any of the following provisions (see General Instructions A.2. below):

Written communications pursuant to Rule 425 under the Securities Act (17 CFR 230.425)

Soliciting material pursuant to Rule 14a-12 under the Exchange Act (17 CFR 240.14a-12)

Pre-commencement communications pursuant to Rule 14d-2(b) under the Exchange Act (17 CFR 240.14d-2(b))

Pre-commencement communications pursuant to Rule 13e-4(c) under the Exchange Act (17 CFR 240.13e-4(c))

Securities registered pursuant to Section 12(b) of the Act: None

Title of each class

Trading Symbol(s)

Name of each exchange on which registered

None

None

None

 

Indicate by check mark whether the registrant is an emerging growth company as defined in Rule 405 of the Securities Act of 1933 (§ 230.405 of this chapter) or Rule 12b-2 of the Securities Exchange Act of 1934 (§ 240.12b-2 of this chapter).

Emerging growth company

 

If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act.

1

 


ITEM 1.05 Material Cybersecurity Incidents.

 

Since the date of the original filing, River's investigation has progressed. River has determined that an unauthorized threat actor accessed portions of its network and removed certain data from its environment. River is working to determine the nature and scope of the information involved, including whether any personally identifiable information was affected. As part of its response, River took steps to attempt to suppress the affected data, including obtaining representations from the threat actor that it deleted the data in its possession.

 

As of the date of this filing, the full nature, scope, and impact of the incident have not yet been determined. River has not yet confirmed whether the incident is reasonably likely to materially impact its business or financial condition. River will file an amendment to this Current Report on Form 8-K within four business days after it determines that such information is available.

 

ITEM 9.01 Financial Statements and Exhibits.

 

(d) Exhibits

 

104

 

Cover Page Interactive Data File (embedded within the Inline XBRL document)

 

 

SIGNATURES

Pursuant to the requirements of the Securities Exchange Act of 1934, the registrant has duly caused this report to be signed on its behalf by the undersigned hereunto duly authorized.

 

 

 

 

 

 

 

 

 

 

 

 

RIVER FINANCIAL CORPORATION

 

 

 

 

Date: July 30, 2026

 

 

 

By

 

/s/ James M. Stubbs

 

 

 

 

 

 

James M. Stubbs

 

 

 

 

 

 

Chief Executive Officer

 

2

 


Filing Exhibits & Attachments

1 document