Treasury
3-MO 3.83% -7bp 6-MO 3.97% -10bp 1-YR 4.04% -5bp 2-YR 4.22% -4bp 3-YR 4.29% -2bp 5-YR 4.37% +2bp 7-YR 4.51% +4bp 10-YR 4.67% +6bp 20-YR 5.21% +10bp 30-YR 5.20% +11bp 3-MO 3.83% -7bp 6-MO 3.97% -10bp 1-YR 4.04% -5bp 2-YR 4.22% -4bp 3-YR 4.29% -2bp 5-YR 4.37% +2bp 7-YR 4.51% +4bp 10-YR 4.67% +6bp 20-YR 5.21% +10bp 30-YR 5.20% +11bp 3-MO 3.83% -7bp 6-MO 3.97% -10bp 1-YR 4.04% -5bp 2-YR 4.22% -4bp 3-YR 4.29% -2bp 5-YR 4.37% +2bp 7-YR 4.51% +4bp 10-YR 4.67% +6bp 20-YR 5.21% +10bp 30-YR 5.20% +11bp 3-MO 3.83% -7bp 6-MO 3.97% -10bp 1-YR 4.04% -5bp 2-YR 4.22% -4bp 3-YR 4.29% -2bp 5-YR 4.37% +2bp 7-YR 4.51% +4bp 10-YR 4.67% +6bp 20-YR 5.21% +10bp 30-YR 5.20% +11bp 3-MO 3.83% -7bp 6-MO 3.97% -10bp 1-YR 4.04% -5bp 2-YR 4.22% -4bp 3-YR 4.29% -2bp 5-YR 4.37% +2bp 7-YR 4.51% +4bp 10-YR 4.67% +6bp 20-YR 5.21% +10bp 30-YR 5.20% +11bp 3-MO 3.83% -7bp 6-MO 3.97% -10bp 1-YR 4.04% -5bp 2-YR 4.22% -4bp 3-YR 4.29% -2bp 5-YR 4.37% +2bp 7-YR 4.51% +4bp 10-YR 4.67% +6bp 20-YR 5.21% +10bp 30-YR 5.20% +11bp
US Treasury par yield curve · Jul 29 · Source: U.S. Treasury
Thursday, July 30, 2026
U.S. Edition
Disclosure

An Alabama bank has told the SEC it obtained representations from the threat actor that the stolen data was deleted

A close photograph of a dark metal sheet punched all over with raised circular bosses, each pierced by a small square hole, the surface scuffed and lit from one side, filling the whole frame with no text, label or background visible.
Photo: Tomás Asurmendi / Pexels

One sentence in Thursday's filing appears nowhere in the four before it.

River Financial Corporation, the Prattville holding company for River Bank and Trust, has been amending the same cybersecurity disclosure since 25 June. Thursday's version, the fourth amendment, says that as part of its response the company "took steps to attempt to suppress the affected data, including obtaining representations from the threat actor that it deleted the data in its possession."

That is a bank telling the Securities and Exchange Commission it has a promise from the party that took its data. The filing does not say how the promise was obtained. It does not say whether anything was paid, and this brief does not suggest that anything was.

Five filings, five weeks

The original Form 8-K went in on 25 June. It said an unauthorised threat actor gained access to the network on or about 16 June, that River identified the activity on or about 19 June, and that ransomware had been deployed across portions of its server environment. Administrative accounts were disabled. Systems were taken offline. A third-party forensic firm came in.

Then the disclosures arrive roughly weekly, and each one hardens the previous one. On 6 July the company had "reason to believe that certain data was potentially impacted" and no evidence that accounts had been. On 10 July the belief became a determination: the threat actor "accessed portions of its network and removed certain data from its environment." That same filing reported two class actions. On 17 July there were four, and the company told the SEC that the principal issue in each is whether the attacker acquired customer information.

Thursday's amendment drops the litigation paragraph and adds the suppression one.

What the company still does not know

The rest of the filing is a repetition of the position River has held since June. The full nature, scope and impact of the incident have not been determined. Whether the incident is reasonably likely to materially impact the business or the financial condition has not been confirmed. Another amendment is promised within four business days of the company knowing.

Item 1.05 is the item Congress and the SEC built for exactly this, and River is using it as designed, which is to say it is publishing what it knows on the day it knows it. The cost of that discipline is that the public record now contains five documents, and the newest one says the investigation is still open on the question of whose information left the building.

The filing runs to two pages and carries no exhibit. It was accepted by EDGAR at 11:40 Eastern and signed by James M. Stubbs, the chief executive.

The document: River Financial Corporation, Form 8-K/A, filed 30 July 2026, accession 0001193125-26-325324, accepted by EDGAR at 11:40:01 Eastern. Date of earliest event reported, 19 June 2026. Alabama, Commission file number 333-205986, IRS employer identification number 46-1422125, 2611 Legends Drive, Prattville, Alabama 36066. No securities registered under section 12(b). Items on the submission header: 1.05 and 9.01. Item 1.05 text read in full and quoted here verbatim: 'Since the date of the original filing, River's investigation has progressed. River has determined that an unauthorized threat actor accessed portions of its network and removed certain data from its environment. River is working to determine the nature and scope of the information involved, including whether any personally identifiable information was affected. As part of its response, River took steps to attempt to suppress the affected data, including obtaining representations from the threat actor that it deleted the data in its possession. As of the date of this filing, the full nature, scope, and impact of the incident have not yet been determined. River has not yet confirmed whether the incident is reasonably likely to materially impact its business or financial condition. River will file an amendment to this Current Report on Form 8-K within four business days after it determines that such information is available.' Signed 'Date: July 30, 2026 By /s/ James M. Stubbs, Chief Executive Officer'. THE FOUR PRIOR FILINGS IN THE SEQUENCE WERE ALSO RETRIEVED AND READ IN FULL, to establish which sentence is new. (1) Form 8-K filed 25 June 2026, accession 0001193125-26-282946, Item 1.05, verbatim: 'On or about June 16, 2026, an unauthorized threat actor gained access to the network environment of River Financial Corporation, including River Bank & Trust (together, "River"). River identified the activity on or about June 19, 2026, and determined that ransomware had been deployed across portions of its server environment. River promptly took containment measures, including disabling affected administrative accounts and taking impacted systems offline. River, with the assistance of a third-party forensic firm, is investigating the nature and scope of the incident, including whether any personally identifiable information was subject to unauthorized access or exfiltration.' Also: 'Certain operations have been impacted, but River is working with external cybersecurity professionals to fully restore these operations.' (2) Form 8-K/A filed 6 July 2026, accession 0001193125-26-295704: 'River has reason to believe that certain data was potentially impacted... To date, there is no evidence that accounts have been impacted.' (3) Form 8-K/A filed 10 July 2026, accession 0001193125-26-300763: first appearance of 'accessed portions of its network and removed certain data from its environment'; also 'To date, River is not aware of any reports of fraud as a direct result of this incident' and 'Following public disclosure of the incident, two class action lawsuits were filed against River relating to the incident. River is evaluating the complaints and intends to respond in ordinary course.' (4) Form 8-K/A filed 17 July 2026, accession 0001193125-26-307288: 'A third class action was filed against River on July 10, 2026 and a fourth class action was filed against River on July 16, 2026. The principal issue in each case is whether cybercriminals have acquired access to River's customers' personal identifiable information.' The suppression and representations sentence appears in NONE of these four and is new to the 30 July filing. Filing history confirmed against data.sec.gov/submissions/CIK0001641601.json, retrieved 30 July 2026: entity name River Financial Corp, ticker RVRF, business address Prattville AL. No press release, exhibit or Item 8.01 accompanies the 30 July amendment; the only exhibit listed is 104, the cover page inline XBRL. All documents read end to end 30 July 2026..