US bank places trust in ransomware crew that promised to delete its data

https://image.theregister.com/5266120.jpg?imageId=5266120&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

History suggests this was not wise

Would you trust a ransomware extortionist to delete the data they stole? One bank certainly wants you to. Well over a month into a ransomware cleanup job, River Financial Corporation tells regulators that it “took steps to attempt to suppress the affected data, including obtaining representations from the threat actor that it deleted the data in its possession.”

For context, placing this kind of trust in this kind of individual has been proven to be a bad idea. When globo-cops took down LockBit in 2024, they found evidence that victim data was retained even after the victim had paid the extortion demands.

In its Form 8-K filing with the SEC, River Bank did not explicitly state whether or not it paid any of the criminals’ ransom demands, although ransomware crooks are not commonly known to offer a victim data deletion for free.

The...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE