CSIDB logo
Incident

Artisans’ Bank

Incident posture

Attack window
Aug 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 10:16

Linked entities

Victim
Artisans’ Bank
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Aug 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Delaware-based community bank experienced a data breach after one of its third-party vendors, Marquis Software Solutions, suffered a security incident in which an unauthorized third party may have accessed or obtained sensitive customer data starting as early as mid-August. The bank learned of the breach around late October and confirmed that the compromised information may include names, addresses, and Social Security numbers. Approximately 32,344 individuals were potentially impacted by the incident. The law firm Edelson Lechtzin LLP announced an investigation into potential class action claims on behalf of affected customers.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On October 28, 2025, Artisans' Bank, a Delaware-based community bank that provides personal and business banking services, learned that one of its third-party vendors, Marquis Software Solutions, had suffered a security breach. According to Marquis's investigation, an unauthorized third party may have accessed or obtained sensitive customer data, with the earliest potential exposure dated to August 14, 2025. The bank received notification of the incident on or around October 28, 2025, marking the point at which Artisans' Bank became aware that information belonging to its customers could have been compromised through its vendor relationship. The breach originated not within the bank's own systems but through this external provider, highlighting the role of third-party service providers as an avenue for unauthorized data access. Once notified, the incident fell within the scope of an ongoing data privacy matter that would subsequently attract legal attention on behalf of affected individuals.

The compromised data may include personal information such as customer names, addresses, and Social Security numbers. Approximately 32,344 individuals may have been impacted by the breach. Because the data involved elements commonly used for identity verification and financial account access, the potential exposure carried meaningful implications for affected customers, even though the source articles do not detail specific instances of identity theft or fraud tied to this incident. The scope of the breach, spanning a window from mid-August 2025 through late October 2025, indicated that unauthorized access to the vendor environment may have continued for roughly two and a half months before the bank was alerted. Artisans' Bank itself is described as a community institution serving Delaware, and the incident affected a defined subset of its customer base rather than the institution's broader operational infrastructure.

Following the disclosure of the breach, Edelson Lechtzin LLP, a national class action law firm with offices in Pennsylvania and California, announced an investigation into data privacy claims on behalf of Artisans' Bank customers whose data may have been compromised. The law firm indicated that it was exploring a potential class action lawsuit to seek legal remedies for the affected individuals. Marc H. Edelson, Esq., of Edelson Lechtzin LLP, was identified as the contact for individuals interested in discussing the matter. The law firm published its investigation notice on December 27, 2025, roughly two months after the bank first learned of the incident, signaling the beginning of formal legal scrutiny into how the breach occurred and what recourse affected customers might pursue. The bank's own public-facing communication regarding protective steps advised recipients of any data breach notification to monitor account statements and credit reports for unauthorized activity.

Sources

Sources available to members: 1 source.

CSIDB