CSIDB logo
Incident

Marquis

Incident posture

Attack window
Aug 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 10:18

Linked entities

Victim
Marquis
Threat actors
0 actors
Sources
7 sources

Timeline

Occurred
Aug 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack on the Texas-based fintech company Marquis exposed the personal and financial data of more than 672,000 individuals, including names, dates of birth, addresses, Social Security numbers, taxpayer identification numbers, and bank account, debit, and credit card details. The intrusion occurred when hackers exploited information stolen from the company's firewall provider, SonicWall, whose cloud backup service had been compromised earlier in the year, allowing the attackers to obtain firewall configuration files and credentials that gave them a roadmap into Marquis's internal network. Once inside, the threat actors exfiltrated sensitive customer data and deployed ransomware, with more than half of those affected residing in Texas. The incident has since led the victim company to file suit against SonicWall, alleging negligence in securing its backup service and delaying disclosure of the full scope of the breach.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

In August 2025, Marquis Marketing Services, a Texas-based fintech company headquartered in Plano that provides data analytics, marketing, and compliance solutions to hundreds of banks and credit unions, identified a data security incident in which attackers gained unauthorized access to its systems and subsequently deployed ransomware. The company immediately activated its incident response protocols, proactively taking affected systems offline to protect both its own data and the customer information it holds on behalf of the financial institutions it serves. Marquis engaged third-party cybersecurity experts to conduct a comprehensive investigation into the scope and nature of the intrusion and notified law enforcement of the incident. The attackers were able to leverage stolen firewall configuration files and credentials, including service account passwords and emergency scratch codes, which provided them with a detailed blueprint of Marquis's internal network architecture and allowed them to bypass perimeter defenses that would otherwise have blocked unauthorized access. Once inside the network, the threat actors exfiltrated large volumes of sensitive personal and financial data before encrypting systems to extort a ransom payment.

The information stolen during the breach was extensive and included full names, dates of birth, home and postal addresses, phone numbers, Social Security numbers, Taxpayer Identification Numbers, financial account information without security or access codes, debit card numbers, and credit card numbers. Marquis held this data on behalf of dozens of the approximately 700 banks and credit unions it serves, meaning the breach did not directly target the banks' own systems but rather the third-party technology provider that processes and analyzes customer information for them. In filings with state attorneys general and public notifications, Marquis initially declined to provide a precise count of affected individuals, though reports submitted to the Texas Attorney General's Office indicated at least 400,000 people were impacted. As state-by-state notifications progressed, the total scope expanded, with some earlier reporting estimating the count could reach as high as 1.6 million people based on aggregated state filings.

By mid-March 2026, Marquis confirmed through a filing with the Maine Attorney General's Office that the breach affected at least 672,075 individuals, with more than half of those impacted residing in Texas and the remainder spread across multiple other states. This figure represented a downward revision from earlier higher estimates that had been projected based on preliminary state disclosures and the separate notifications issued by affected financial institutions, which had collectively suggested a victim count approaching 780,000 or more. Comparitech, which had previously estimated as many as 1.6 million people could ultimately be affected, acknowledged the revised figure when Marquis provided the updated number. No cybercrime group publicly claimed responsibility for the attack on Marquis, though around the time of the intrusion the Akira ransomware group had been actively exploiting SonicWall firewall vulnerabilities, and a now-removed data breach notice from an Iowa credit union had previously indicated that Marquis may have paid a ransom to the attackers, a claim that the fintech company has neither confirmed nor denied.

The investigation into the root cause of the breach revealed that the attackers had exploited an earlier compromise at SonicWall, Marquis's firewall provider, to obtain the configuration data and credentials necessary to infiltrate Marquis's network. In mid-September 2025, SonicWall publicly disclosed that an unnamed threat actor had gained unauthorized access to its MySonicWall cloud backup service, which stores firewall configuration files containing network rules, access policies, VPN configurations, service credentials for protocols such as LDAP, RADIUS, and SNMP, as well as administrative usernames and passwords when those were stored in the configuration. At the time of its initial disclosure, SonicWall indicated that fewer than 5% of its customers had been affected by the cloud backup breach. However, in October 2025, the firewall manufacturer reversed that assessment and confirmed that firewall configuration data and credentials associated with all customers using the cloud backup service, including Marquis, had been accessed by the threat actors. Marquis had recently begun using SonicWall's firewalls to protect its network at the time of the breach, and the company confirmed it had stored a backup of its firewall configuration file in SonicWall's cloud.

The connection between the SonicWall cloud backup breach and the subsequent ransomware attack on Marquis formed the basis of a lawsuit filed by Marquis in February 2026 in the U.S. District Court for the Eastern District of Texas, in which the fintech company sought a jury trial and damages from SonicWall. In its complaint, Marquis alleged that SonicWall failed to properly secure its cloud backup system, which exposed firewall configuration files, encrypted credentials, and detailed network architecture tied to customer environments, effectively providing them with a roadmap into Marquis's internal network. The complaint further alleged that SonicWall knew its cloud backup service had been compromised but did not promptly disclose the full scope of the breach, initially reassuring customers that firewall protections were not affected and thereby delaying Marquis's ability to take protective action. Marquis CEO Satin Mirchandani stated that SonicWall had allegedly failed to secure its backup service, causing the company to suffer significant reputational, operational, and financial harm, and that SonicWall had allowed a threat actor to obtain the keys to bypass its line of defense and walk directly into Marquis's internal network, the very thing the firewall was supposed to prevent. The complaint also alleged that SonicWall made a code change to one of its APIs in February 2025 that created a vulnerability exploitable by threat actors, allowing them to access customer firewall configuration backup files without proper authentication by guessing predictable firewall serial numbers.

SonicWall, in response to the lawsuit, asked Marquis for evidence to substantiate its claims and stated that there was no new evidence establishing a connection between the SonicWall security incident reported in September 2025 and ongoing global ransomware attacks on firewalls and other edge devices. The firewall manufacturer also noted that SonicWall has not publicly stated when hackers were first able to gain access to its own systems, and the precise root cause of the breach at SonicWall has not been publicly disclosed. In communications to its own customers in late January 2026, Marquis confirmed that its third-party investigation determined that the hackers obtained information about its firewall during the breach at SonicWall and that this information was used to circumvent its firewall protections. The company also stated that it had reviewed whether a patch it had failed to roll out at the time of the breach could have been to blame but concluded that the patch related to a flaw was not exploitable in a way that could have allowed hackers to access the company's data. The company began notifying affected individuals in December 2025, with notifications continuing into early 2026 as state-by-state filings were submitted to various attorneys general across the United States.

Sources

Sources available to members: 7 sources.

CSIDB