Phishing Campaign Spoofing River Financial Underlines Custody Sector’s Fraud Gap
Fake emails impersonating the Bitcoin custodian expose how brand trust in institutional-grade platforms can be weaponised by scammers.

A phishing campaign impersonating River Financial, the US-based Bitcoin brokerage and custody firm, is circulating fraudulent emails urging recipients to update account agreements or schedule calls with fake company representatives, according to Crypto Briefing. The firm itself has not been compromised, but the episode has renewed scrutiny of how brand trust in institutional-grade custodians can be exploited by fraudsters targeting irreversible Bitcoin transactions.
Crypto Briefing reports that the emails mimic River Financial’s visual identity and tone, using urgency-laced language to push recipients towards clicking through to what are likely credential-harvesting phishing pages. A second variant of the scam invites victims to schedule a call, adding a human element that can allow a live fraudster to extract further sensitive information through direct conversation.
Brand impersonation, not a breach
River Financial, founded in 2019 by Alex Leishman and Andrew Benson and backed at an early stage by Polychain Capital, operates a full-reserve, Bitcoin-only brokerage and custody model. The company’s underlying systems and client accounts remain unaffected, according to Crypto Briefing, which characterises the incident as brand impersonation rather than a platform-level security failure.
That distinction matters for regulators and institutional counterparties assessing custody risk. Unlike a breach of internal infrastructure, impersonation campaigns exploit the reputational capital a platform has built with users, rather than any technical vulnerability in its own systems.
Why custody platforms remain a target
Phishing attempts against cryptocurrency platforms have grown more frequent, Crypto Briefing notes, with Bitcoin holders representing a particularly attractive target given the irreversibility of on-chain transactions. Once funds leave a wallet, there is no bank to call and no chargeback mechanism available to victims.
River Financial has positioned itself as a trust-focused, institutional-grade alternative to conventional exchanges, an emphasis on security and education that, in this instance, may make impersonation more effective rather than less. Users who associate the brand with rigorous safeguards could be more inclined to lower their guard when contacted under its name.
Guidance for account holders
Standard defensive measures apply, according to the report: recipients should scrutinise sender addresses closely, avoid clicking links in unsolicited emails, and navigate directly to River Financial’s website by typing the URL manually rather than following embedded links. An email that generates a sense of urgency or threatens consequences for inaction should itself be treated as a warning sign.
Crypto Briefing adds that legitimate financial services firms rarely request agreement updates through emailed links with imposed deadlines, nor do they typically cold-schedule calls to discuss account details. Two-factor authentication via a hardware key or authenticator app, rather than SMS, alongside unique passwords per platform, is recommended. Suspicious emails should be forwarded to a company’s official support channel rather than engaged with directly.
Read more: Block’s $45m Cash App Settlement Signals Tougher Fraud Rules for Bitcoin-Linked Fintechs



Leave a Reply