Menu
Browse

Cyber Incident Victim: River City Bank

Date:

Sep 2020

Location:

United States of America

Summary

River City Bank experienced an insider incident where an employee improperly downloaded customer data onto a personal storage device and transmitted it to an unauthorized third party, exceeding their legitimate access privileges. The bank swiftly revoked the employee’s access, initiated an investigation, and engaged law enforcement, while notifying affected customers and regulators. No evidence of subsequent data misuse was identified at the time of disclosure.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On September 29, 2020, River City Bank identified unauthorized activity involving an employee who downloaded customer data to a personal storage device outside their authorized duties. The bank immediately blocked the employee’s system access upon discovery and initiated an internal investigation. Law enforcement agencies were engaged to assist with the inquiry. The compromised data was subsequently transferred by the employee to an unidentified third party, though the bank’s notification did not specify the recipient’s identity or the intended purpose of the data transfer. No legitimate business reason existed for this data movement, as it fell outside the employee’s normal responsibilities.

Cyber Incident Image

River City Bank notified affected customers about the breach and submitted documentation to the California Attorney General’s Office as part of regulatory compliance. The bank’s public disclosure confirmed the incident stemmed solely from insider wrongdoing without external system intrusion. Investigators found no evidence indicating actual misuse of the stolen customer information at the time of notification. The bank did not disclose the number of affected customers, data categories involved, or technical methods used to detect the unauthorized download. Containment efforts focused on revoking the employee’s access privileges and securing internal systems, though no additional security enhancements or forensic findings were detailed in the submitted notification. Law enforcement involvement remained active as of the notification date.

Sources
Sources available to members
1 source