Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
third-party-vendor-breachransomware-group-operationfinancial-sector-threatgovernment-diplomatic-threat

Multiple High-Profile Data Leaks and Ransomware Attacks Impact Financial and Government Entities

Updated 3mo agoFirst seen Dec 29, 20254 sources

Several significant data leaks and ransomware incidents have surfaced, affecting a range of organizations including Banco Vimenca, WIRED subscribers, Mexico’s Tax Administration Service (SAT), and New Zealand’s Neighbourly platform. Threat actors have claimed responsibility for exposing sensitive data such as government financial records, large-scale subscriber information, and user communications, with some incidents linked to ransomware groups. While the authenticity of these dark web postings remains unverified, the breadth of affected entities highlights ongoing risks to both financial institutions and government agencies from cybercriminal activity.

In the United States, two banks—Artisans' Bank and VeraBank—have notified thousands of customers that their personal information was compromised in a ransomware attack on Marquis Software, a vendor providing data analytics and communication services to financial institutions. The attack, traced to a vulnerability in a SonicWall firewall, resulted in the exposure of names and Social Security numbers, though the banks’ own systems were not directly breached. These incidents underscore the persistent threat posed by supply chain vulnerabilities and the importance of robust third-party risk management for organizations handling sensitive data.

Share:
Multiple High-Profile Data Leaks and Ransomware Attacks Impact Financial and Government Entities
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Dec 29, 20256mo ago

VeraBank notifies customers affected by Marquis supplier breach

In late December 2025, VeraBank also began notifying customers that their data was exposed in the Marquis Software incident. The notifications added to estimates that the total number of affected individuals exceeded 1.4 million across multiple institutions.

Artisans' Bank begins notifying customers of Marquis-linked breach

In late December 2025, Artisans' Bank disclosed that customer information was compromised through the Marquis Software attack and began notifying affected individuals. Reported exposed data included personal identifiers and financial information, and the bank offered credit monitoring.

Nov 26, 20257mo ago

Marquis breach first disclosed to regulators in Iowa

Marquis Software first publicly disclosed the incident in a notification to Iowa regulators on 2025-11-26. The filing described exposure of sensitive personal and financial data tied to customers of banking clients.

Aug 14, 202510mo ago

Marquis notifies law enforcement and affected institutions

After discovering the August attack, Marquis Software notified federal law enforcement and informed affected client institutions about the breach. The company did not publicly attribute the attack to a specific ransomware group.

Ransomware attack hits Marquis Software via SonicWall firewall

On 2025-08-14, attackers breached Marquis Software Solutions' environment through its SonicWall firewall in a ransomware-related incident. The compromise exposed data that Marquis maintained for banks and credit unions, rather than directly breaching the financial institutions' own systems.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

12 LINKEDOpen in app
Threat actors
1 linked
Malware
1 linked
Organizations
10 linked
ComparitechMarquisVeraBankArtisans' BankRapid7WIREDCommunity 1st Credit UnionBanco VimencaNeighbourlyMarquis Software
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.