Cyber Incident Victim: River City Bank
Date:
Sep 2020
Location:
United States of America
Summary
River City Bank experienced an insider incident where an employee improperly downloaded customer data onto a personal storage device and transmitted it to an unauthorized third party, exceeding their legitimate access privileges. The bank swiftly revoked the employee’s access, initiated an investigation, and engaged law enforcement, while notifying affected customers and regulators. No evidence of subsequent data misuse was identified at the time of disclosure.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On September 29, 2020, River City Bank identified unauthorized activity involving an employee who downloaded customer data to a personal storage device outside their authorized duties. The bank immediately blocked the employee’s system access upon discovery and initiated an internal investigation. Law enforcement agencies were engaged to assist with the inquiry. The compromised data was subsequently transferred by the employee to an unidentified third party, though the bank’s notification did not specify the recipient’s identity or the intended purpose of the data transfer. No legitimate business reason existed for this data movement, as it fell outside the employee’s normal responsibilities.

River City Bank notified affected customers about the breach and submitted documentation to the California Attorney General’s Office as part of regulatory compliance. The bank’s public disclosure confirmed the incident stemmed solely from insider wrongdoing without external system intrusion. Investigators found no evidence indicating actual misuse of the stolen customer information at the time of notification. The bank did not disclose the number of affected customers, data categories involved, or technical methods used to detect the unauthorized download. Containment efforts focused on revoking the employee’s access privileges and securing internal systems, though no additional security enhancements or forensic findings were detailed in the submitted notification. Law enforcement involvement remained active as of the notification date.
