Marquis Software Solutions, a provider of marketing and compliance software to over 700 banks and credit unions, experienced a significant data breach after ransomware attackers exploited a vulnerability in its SonicWall firewall. The breach, detected on August 14, allowed attackers to access files containing sensitive information stored by Marquis on behalf of its financial institution clients, potentially exposing the personal data of at least 250,000 individuals.
The compromised data may include names, addresses, phone numbers, dates of birth, Social Security numbers, tax identification numbers, and financial account information. Marquis Software stated that the incident was limited to its own environment, but the breach has affected multiple financial institutions whose customer data was managed by the vendor. The company is working with digital forensic investigators to assess the full scope of the breach and has notified affected parties accordingly.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Following the breach, Marquis said it patched firewalls, enforced multifactor authentication, restricted VPN access, and applied additional controls such as geo-IP filtering. These measures were disclosed publicly as part of the company's response to reduce future risk.
By 2025-12-04, Marquis had begun notifying affected consumers directly about the exposure of personal and financial information. The company said it had no evidence of misuse at that time and offered free credit monitoring and identity theft protection.
By early December 2025, breach notices filed with multiple state attorneys general showed the incident had spread across at least 74 banks and credit unions. Reported victim counts rose from at least 250,000 people to more than 400,000, then 721,000 and over 780,000 as additional institutions disclosed impacts.
Between late October and late November 2025, Marquis notified affected banks and credit unions that customer data had been exposed in the breach. Early disclosures indicated the incident affected dozens of U.S. financial institutions served by the vendor.
Marquis identified the attack on the same day it occurred and launched an investigation into the compromise. The company also engaged cybersecurity experts and notified federal authorities, according to later disclosures.
On 2025-08-14, attackers exploited a vulnerability in Marquis Software Solutions' SonicWall firewall and gained unauthorized access to the company's network. The intrusion led to a ransomware incident and theft of files from Marquis systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
reuters.com
Open sourcedatabreaches.net
Open sourcesecurityaffairs.com
Open sourcesocradar.io
Open sourcebankinfosecurity.com
Open sourcebleepingcomputer.com
Open sourcegovinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.