Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
third-party-vendor-breachransomware-group-operationfinancial-sector-threatbreach-disclosure-notification

Ransomware Breach at Marquis Software Solutions Exposes Bank Customer Data

Updated 3mo agoFirst seen Dec 3, 20257 sources

Marquis Software Solutions, a provider of marketing and compliance software to over 700 banks and credit unions, experienced a significant data breach after ransomware attackers exploited a vulnerability in its SonicWall firewall. The breach, detected on August 14, allowed attackers to access files containing sensitive information stored by Marquis on behalf of its financial institution clients, potentially exposing the personal data of at least 250,000 individuals.

The compromised data may include names, addresses, phone numbers, dates of birth, Social Security numbers, tax identification numbers, and financial account information. Marquis Software stated that the incident was limited to its own environment, but the breach has affected multiple financial institutions whose customer data was managed by the vendor. The company is working with digital forensic investigators to assess the full scope of the breach and has notified affected parties accordingly.

Share:
Ransomware Breach at Marquis Software Solutions Exposes Bank Customer Data
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Dec 4, 20257mo ago

Marquis discloses post-breach security hardening measures

Following the breach, Marquis said it patched firewalls, enforced multifactor authentication, restricted VPN access, and applied additional controls such as geo-IP filtering. These measures were disclosed publicly as part of the company's response to reduce future risk.

Marquis begins notifying affected individuals and offers credit monitoring

By 2025-12-04, Marquis had begun notifying affected consumers directly about the exposure of personal and financial information. The company said it had no evidence of misuse at that time and offered free credit monitoring and identity theft protection.

Dec 3, 20257mo ago

State breach filings reveal growing customer impact across institutions

By early December 2025, breach notices filed with multiple state attorneys general showed the incident had spread across at least 74 banks and credit unions. Reported victim counts rose from at least 250,000 people to more than 400,000, then 721,000 and over 780,000 as additional institutions disclosed impacts.

Oct 25, 20258mo ago

Marquis starts notifying affected financial institutions

Between late October and late November 2025, Marquis notified affected banks and credit unions that customer data had been exposed in the breach. Early disclosures indicated the incident affected dozens of U.S. financial institutions served by the vendor.

Aug 14, 202510mo ago

Marquis detects the ransomware attack and begins investigation

Marquis identified the attack on the same day it occurred and launched an investigation into the compromise. The company also engaged cybersecurity experts and notified federal authorities, according to later disclosures.

Attackers exploit Marquis SonicWall firewall and breach its network

On 2025-08-14, attackers exploited a vulnerability in Marquis Software Solutions' SonicWall firewall and gained unauthorized access to the company's network. The intrusion led to a ransomware incident and theft of files from Marquis systems.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

18 LINKEDOpen in app
Threat actors
1 linked
Malware
1 linked
Organizations
15 linked
MarquisSonicwallNorway Savings BankSOCRadarMaine State Credit UnionCommunity Banks and Credit Unions (United States)Maine Attorney GeneralCoVantage Credit UnionCommunity 1st Credit UnionArctic WolfRapid7AkiraComparitechAkira RansomwareUS Attorney General offices
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.