Ransomware attacks have evolved significantly over the past few years, with cybercriminals increasingly relying on a tactic known as double extortion. In these attacks, hackers not only encrypt an organization’s data to disrupt operations but also steal sensitive information before launching the encryption process. This stolen data becomes an additional bargaining tool. If the victim refuses to pay the ransom or delays negotiations, the attackers often threaten to publish or sell the stolen information to third parties, increasing the pressure to comply with their demands.
Despite repeated warnings from cybersecurity experts and law enforcement agencies, some organizations continue to trust the promises made by ransomware groups after paying a ransom. One such case involves River Bank and Trust, a subsidiary of River Financial Corporation based in Alabama. The bank disclosed that it believed the attackers had deleted the stolen data after receiving the ransom payment, relying on assurances provided by the cybercriminals.
While this may appear to be a practical decision from a business continuity perspective, it highlights the difficult choices organizations face during ransomware incidents. In many cases, recovering encrypted systems from backups can be time-consuming, costly, or even impossible if the backups have also been compromised. As a result, some businesses choose to pay the ransom in the hope of quickly restoring operations and preventing further damage.
However, cybersecurity professionals and law enforcement authorities consistently advise against making ransom payments. Paying cybercriminals not only encourages future attacks by demonstrating that extortion can be profitable, but it also offers no guarantee that the stolen information will actually be deleted. Victims have little or no way to verify whether hackers have honored their promises, leaving them exposed to future risks such as data leaks, identity theft, or additional extortion attempts.
A notable example supporting this concern emerged in 2024 when Europol, working alongside several international law enforcement agencies, dismantled the infrastructure of the notorious LockBit ransomware gang. During the operation, investigators seized servers containing extensive records of victim organizations. Surprisingly, the seized data included information belonging not only to companies that had refused to pay but also to those that had complied with ransom demands. This discovery demonstrated that ransomware groups often retain stolen data regardless of any assurances they provide after receiving payment.
The River Bank incident came to light through a filing submitted to the U.S. Securities and Exchange Commission (SEC) on June 16. According to the disclosure, the bank experienced a ransomware attack that compromised its systems. The institution stated that it believes the threat actors have removed or erased the stolen data from their storage infrastructure and expressed confidence that customers are unlikely to face harm resulting from the breach of personal information.
At the time of the disclosure, the identity of the ransomware group responsible for the attack had not been publicly revealed. Investigations into the incident are expected to continue as authorities work to determine the full scope of the breach and identify those responsible.
The incident serves as another reminder that while paying a ransom may appear to resolve an immediate crisis, organizations should remain cautious about placing trust in cybercriminals. There is no reliable mechanism to verify that stolen data has been permanently deleted, making robust cybersecurity defenses, secure backups, and well-prepared incident response plans the most effective long-term strategies against ransomware attacks.
Join our LinkedIn group Information Security Community!
