River City Bank employee
Attribution profile
- Type
- Insider - Disgruntled
- Location
- United States of America
- Known incidents
- 1 incident
- Sources
- 1 source
- First seen
- 2020-09-29
- Last seen
- 2020-09-29
- Updated
- 2026-07-30 23:26
- Aliases
- 1 alias
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor is known by the alias River City Bank employee and operates within the United States of America. This individual was identified as an insider with legitimate access to the bank’s internal systems. The actor’s role involved handling customer data as part of normal employment duties. No further aliases or affiliations have been publicly disclosed.
On September 29, 2020, the actor downloaded customer information from the bank’s systems onto a personal storage device. The download was performed outside the scope of the employee’s authorized duties. After copying the data, the actor transmitted the information to an unauthorized third party. The specific nature of the data and the identity of the third party were not detailed in the public notification.
Upon discovery, River City Bank immediately revoked the actor’s access to its networks and systems. The bank launched an internal investigation and involved law enforcement officials. Affected customers and relevant regulators were notified of the incident. The notification emphasized that the bank had found no evidence of data misuse at the time of disclosure.
No additional campaigns or operations have been publicly linked to this actor beyond the described insider incident. The case remains a singular example of unauthorized data exfiltration by an employee. Consequently, the actor’s activity is confined to this specific event as reported. No further public updates regarding the actor’s status or actions have been released.
Incidents
Attributed incidents are available to members.
1 incidentSources
Sources available to members: 1 source.