A major breach at Marquis Software Solutions exposed sensitive data tied to more than seventy U.S. financial institutions. Attackers gained access through a compromised SonicWall firewall and stole files containing personal and financial information. Notifications submitted by banks in multiple states show that more than 400,000 customers were affected. Marquis reports no evidence of misuse so far, yet filings suggest a ransom was paid to prevent public release of stolen data.
Relevant Source (Reuters): Fintech firm Marquis notifies affected business after ransomware breach
Reuters reports that Texas-based fintech Marquis suffered an August 14, 2025 ransomware attack via a SonicWall firewall that exposed sensitive customer data for U.S. banks and credit unions.
Quick Facts
- Over 74 banks and credit unions impacted across the U.S.
- Breach occurred August 14, 2025 after a SonicWall firewall compromise.
- Data included names, addresses, SSNs, TINs, account details, and dates of birth.
- More than 400,000 customers affected according to state filings.
- Deleted filing indicated Marquis paid ransom to stop data exposure.
- Company has since implemented new security controls and hardened access.
Marquis Vendor Breach Basics
Marquis Software Solutions supplies analytics, CRM tools, compliance reporting, and marketing services to more than 700 financial institutions. The company disclosed a ransomware attack that allowed threat actors to steal files containing customer data received from its clients. Notifications filed in multiple states confirm that banks and credit unions across the country were affected. Regulators were told the stolen information included personally identifiable details that criminals typically target for fraud.
- Attackers breached the network through a SonicWall firewall.
- Stolen data included SSNs, TINs, and financial account information without access codes.
- More than seventy financial institutions reported customer impact.
The breadth of institutions involved shows how a single service provider can create significant downstream exposure for the financial sector.
Relevant Source (SecurityWeek): Marquis Data Breach Impacts Over 780,000 People
SecurityWeek details how ransomware attackers exploited a SonicWall firewall at Marquis, stole customer files for hundreds of banks and credit unions, and exposed sensitive personal and financial data.
Why Vendor Breaches Matter
A breach at a vendor that aggregates sensitive data can ripple across every institution connected to it. Financial organizations rely heavily on third party platforms to manage analytics and regulatory tasks so weak points in those systems introduce shared risk. Large amounts of personal and account data give attackers strong leverage for identity theft, synthetic fraud, and social engineering. Regulators pay close attention to these incidents because customer trust and sector stability depend on strong data handling practices.
- Customer information can be used for targeted financial fraud.
- Institutions may face compliance scrutiny and incident response costs.
- Ransom payments raise concerns about long term exposure and attacker incentives.
- SonicWall vulnerabilities have been a favored entry point for ransomware groups.
- Growing reliance on cloud and analytics vendors magnifies third party risk.
The scale of affected institutions positions this event as a reminder that vendor breaches often spread wider than direct attacks on banks themselves.
Relevant Source (NCUA): FAQs on Ransomware and Supply Chain Risk Management
This NCUA guidance explains how ransomware and third party vendor weaknesses can threaten entire financial institutions by exposing shared systems, data, and ICT supply chains.
Practical Steps After This Breach
Banks and credit unions linked to Marquis should verify whether any of their customer records were part of the compromised files. Customers who receive notice should treat the alert seriously and take steps to reduce fraud risk. Actions such as monitoring accounts, updating passwords, and enabling multifactor authentication provide practical protection. Institutions should confirm that Marquis’ updated security controls align with their own vendor risk standards.
Recommended actions include:
- Review breach notifications for institution specific impact.
- Set fraud alerts or credit freezes with major bureaus.
- Change passwords and enable MFA on financial and email accounts.
- Watch for phishing attempts that reference personal details.
- Confirm that vendors have patched, audited, and rotated all VPN credentials.
Careful follow through limits downstream damage even when attackers have already accessed sensitive information.
Relevant Source (FTC): What To Do After a Data Breach
The FTC outlines concrete steps consumers should take after their data is exposed, including monitoring accounts, changing passwords, and using fraud alerts or credit freezes, which aligns directly with the actions recommended in this section.
Akira, SonicWall And Your Risk
Ransomware groups continue to exploit SonicWall vulnerabilities because these devices sit at the network edge and often store cached authentication data. Akira in particular has used CVE 2024 40766 to harvest VPN credentials and one time passcode seeds. Many organizations patched the flaw yet did not reset credentials, giving attackers ongoing access even to updated devices. Marquis’ decision to rotate passwords, enforce MFA, delete old accounts, and lock out repeated VPN attempts signals an understanding of how these intrusions typically unfold.
Financial institutions increasingly depend on shared service providers for compliance, analytics, and customer outreach. When a vendor is compromised, the incident becomes a sector wide event that tests how well organizations vet third party security. Breaches like this highlight the importance of strong patching discipline, credential hygiene, geo filtering, and continuous monitoring across every external connection.
Relevant Source (Canadian Centre for Cyber Security): Alert – SSL VPN vulnerability impacting Gen 7 SonicWall Firewalls (CVE-2024-40766) – Update 1
This alert details active ransomware exploitation of SonicWall SSL VPN CVE-2024-40766, including Akira activity and recommended mitigations like credential resets, MFA, and tighter monitoring, which directly matches the long term SonicWall and ransomware risk described in this section.
Vendor Breaches And You
Vendor breaches stress how much personal data can move through systems the public never sees. Customers and institutions both benefit from treating these alerts seriously, strengthening authentication, and monitoring accounts for unusual activity. Clear communication, fast credential updates, and consistent security controls reduce exposure and help restore confidence after large scale incidents.
Relevant Source (FINRA): Cybersecurity Advisory – Increasing Cybersecurity Risks at Third-Party Providers
FINRA describes how cyberattacks at third party providers can trigger data breaches, ransomware, and leaked customer information across many financial institutions at once, mirroring the vendor risk highlighted in this conclusion.
FAQ
How many people were affected?
More than 400,000 customers according to state level notifications.
What data was exposed?
Names, addresses, phone numbers, SSNs, TINs, dates of birth, and financial account information without access codes.
Was the stolen data leaked online?
Marquis reports no evidence of misuse. A deleted filing indicated a ransom was paid to stop release.
Who carried out the attack?
Details remain unconfirmed though the techniques match known Akira ransomware activity involving SonicWall VPN access.
Can customers protect themselves now?
Yes. Monitor accounts, place fraud alerts, enable MFA, and watch for phishing tied to exposed information.
Support From JENI Systems
JENI helps users keep their computers stable, clean, and secure in a landscape where breaches and ransomware continue to rise. Local processing and trusted repair methods give everyday users a safer baseline that resists common attack paths. Strong system integrity reduces the chance of corrupted caches, broken services, or outdated components that attackers often exploit.
How JENI Strengthens Your Security
- Removes corrupt system caches and logs that weaken stability.
- Repairs OS components that fail silently and create hidden risk.
- Runs fully local with no tracking or cloud exposure.
JENI cannot prevent every threat yet it creates a cleaner, more resilient device that handles security updates and system checks the way they were designed. A stable operating environment lowers attack surface and cuts off many weak points used by modern ransomware groups. Reliable repairs protect performance and reduce system errors that often mask early intrusion signs. Better stability and privacy support a safer experience across both macOS and Windows.

