Several significant data leaks and ransomware incidents have surfaced, affecting a range of organizations including Banco Vimenca, WIRED subscribers, Mexico’s Tax Administration Service (SAT), and New Zealand’s Neighbourly platform. Threat actors have claimed responsibility for exposing sensitive data such as government financial records, large-scale subscriber information, and user communications, with some incidents linked to ransomware groups. While the authenticity of these dark web postings remains unverified, the breadth of affected entities highlights ongoing risks to both financial institutions and government agencies from cybercriminal activity.
In the United States, two banks—Artisans' Bank and VeraBank—have notified thousands of customers that their personal information was compromised in a ransomware attack on Marquis Software, a vendor providing data analytics and communication services to financial institutions. The attack, traced to a vulnerability in a SonicWall firewall, resulted in the exposure of names and Social Security numbers, though the banks’ own systems were not directly breached. These incidents underscore the persistent threat posed by supply chain vulnerabilities and the importance of robust third-party risk management for organizations handling sensitive data.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
In late December 2025, VeraBank also began notifying customers that their data was exposed in the Marquis Software incident. The notifications added to estimates that the total number of affected individuals exceeded 1.4 million across multiple institutions.
In late December 2025, Artisans' Bank disclosed that customer information was compromised through the Marquis Software attack and began notifying affected individuals. Reported exposed data included personal identifiers and financial information, and the bank offered credit monitoring.
Marquis Software first publicly disclosed the incident in a notification to Iowa regulators on 2025-11-26. The filing described exposure of sensitive personal and financial data tied to customers of banking clients.
After discovering the August attack, Marquis Software notified federal law enforcement and informed affected client institutions about the breach. The company did not publicly attribute the attack to a specific ransomware group.
On 2025-08-14, attackers breached Marquis Software Solutions' environment through its SonicWall firewall in a ransomware-related incident. The compromise exposed data that Marquis maintained for banks and credit unions, rather than directly breaching the financial institutions' own systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
bankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourcesocradar.io
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.