Seventy-four banks and credit unions were breached in August 2025. Not one of them was attacked. The intrusion happened inside a Texas fintech most of their customers had never heard of — a company called Marquis that quietly ran marketing, compliance, and analytics for more than 700 financial institutions. By the time the final count reached regulators in March 2026, 672,075 people had their names, birth dates, addresses, SSNs, taxpayer IDs, and card numbers in criminal hands.
The initial access vector was a single firewall — a SonicWall appliance guarding the vendor’s edge — and the story of how one unpatched edge device became 36+ class-action lawsuits, a vendored countersuit, and the largest banking data compromise of its year is the clearest recent argument that “your vendor’s security is your breach.” This is the anatomy of that attack, and the controls that would have made it impossible.
The Marquis breach (Aug 2025 attack, final tally Mar 2026) was a supply-chain ransomware intrusion through an edge device: attackers compromised the fintech’s SonicWall firewall to enter a network holding regulated customer data for 700+ client banks, exfiltrated PII and card data on 672,075 individuals, and disrupted operations at 74 institutions. It resembled the Akira gang’s SonicWall campaign of the same window (CVE-2024-40766, CVSS 9.3, plus weak SSLVPN account hygiene), though no group claimed it and Akira was not confirmed. The attack dies at five break-points: aggressive edge-device patching (a 9.3-severity flaw patched a year earlier was still exploitable), phishing-resistant MFA on every VPN account, zero-trust segmentation of client data per institution, egress monitoring for mass data movement, and contractual + architectural fourth-party risk control that treats a concentration vendor’s perimeter as your own. For the banks, the hardest lesson is legal, not technical: they held every notification duty while owning none of the compromised infrastructure.
What happened: from one firewall to 74 banks
The verified timeline, reconstructed from Marquis’s AG-office notifications, SecurityWeek reporting, and the Maine AG filing, shows a slow-motion casualty count that took seven months to finalize:
| Date | Event | Significance |
|---|---|---|
| Aug 2024 | SonicWall publishes advisory for CVE-2024-40766 (CVSS 9.3, improper access control); exploitation observed shortly after; vendor later urges mass password resets on Gen5/Gen6 SSLVPN accounts | The fix existed for a full year before the attack |
| Aug–Sep 2025 | Akira ransomware campaign surges through SonicWall appliances, potentially chaining three vectors: the CVE, the SSLVPN Default Users Group risk, and exposed Virtual Office Portals (Rapid7) | The ecosystem-wide assault window in which Marquis was hit |
| Aug 14, 2025 | Attackers enter Marquis’s network through the compromised SonicWall firewall | The single point of failure for the entire supply-chain event |
| Aug 2025 | Marquis discovers the intrusion, enacts response protocols, takes affected systems offline, engages third-party forensic experts, notifies law enforcement | Discovery-to-containment was fast; scoping was not |
| Oct 2025 | File/system review investigating what was stolen completes at end of October | ~2.5 months to determine data types — normal for terabyte-scale review, agonizing for waiting clients |
| Nov 2025 | Sept 2025 MySonicWall/cloud-backup incident becomes public, feeding the blame narrative | Sets up Marquis’s later gross-negligence suit against SonicWall |
| Dec 2025 | Marquis mails notification letters and files breach notices with state AGs; ~780,000 initially projected; clients notify their own customers; unconfirmed report (via a since-removed Iowa credit-union notice) that a ransom was paid | Downstream banks now carry their own notification duties — for a breach they didn’t have |
| Feb 2026 | Comparitech estimates up to 1.6M affected based on multi-state filings and client disclosures | Confusion era — nobody, including clients, knows the true count |
| Mar 2026 | Marquis tells the Maine AG the final number: 672,075 individuals; by now defending 36+ consumer class actions and suing SonicWall for gross negligence | The number is smaller than feared (overlap across multi-institution customers), but the legal machinery is fully ignited |
The style of attack: edge-device ransomware at the trust boundary
Three properties define this attack class, and each one explains why it succeeded where phishing campaigns fail.
1. Edge devices are the new front door — and nobody’s watching them
Firewalls and VPN concentrators occupy a toxic position in enterprise architecture: internet-facing, administratively half-remembered, and holding valid session credentials for the internal network. Ransomware crews — Akira foremost among them — have industrialized exactly this: scan for vulnerable appliances, exploit, harvest SSLVPN sessions, and land inside with a legitimate identity. No user to phish, no email to lure, no malware signature until encryption hour.
In the Marquis window, Rapid7 observed attackers potentially chaining three security risks at once: the year-old CVE-2024-40766, the SSLVPN Default Users Group (which can grant VPN access to users who shouldn’t have it), and publicly exposed Virtual Office Portals. One unpatched, loosely configured appliance plus default group behavior equals a door that opens from the outside.
2. Concentration risk: one breach, multiplied by 700
Marquis is a concentration vendor — a single node through which data for hundreds of regulated institutions flows. That’s precisely why banks adopted it (efficiency, compliance tooling, analytics) and precisely why its compromise was catastrophic: the attacker didn’t need 74 entry points; they needed one. Modern supply-chain economics mean a mid-sized fintech’s perimeter effectively is the perimeter of every client it serves. Regulators have a name for this: systematic one-to-many risk. The banks learned the costs of that topology in December, when each had to notify customers about an intrusion inside infrastructure they neither operated nor could inspect.
3. The multi-client data warehouse
What made the compromise deep wasn’t just access; it was what sat behind the door. Marquis’s platforms held names, addresses, SSNs, dates of birth, taxpayer IDs, and financial account data including card numbers — plumbed in from 700+ institutions for marketing and compliance processing. A regulated data lake with one edge device between it and the internet. That’s not a Marquis sin specifically; it’s the standard architecture of the whole fintech vendor layer. But it converts every perimeter failure into an n-party breach — and teaches every CISO the uncomfortable question: do I actually know which of my vendors holds aggregated multi-client data, and is it segmented per institution?
Attribution: the Akira question
No group has claimed the Marquis attack. Akira — active since 2023, with a documented playbook of edge-device initial access, privilege escalation, backup erasure, and hypervisor-level encryption — was ramping SonicWall exploitation in exactly this window, which made it the early suspect. It has since been effectively exonerated; no ransomware group has taken credit, and the intrusion is characterized by some reports as primarily data theft. An Iowa credit union’s breach notice (since removed) suggested Marquis paid a ransom, which the company has neither confirmed nor denied.
The attribution ambiguity matters less than the pattern: whether the actor was Akira, a clone, or an access broker selling into one, the entry technique is identical and well-documented. Defenders don’t need a name to break the kill chain — the vectors are known, patched, and misconfiguration-auditable today.
The attack chain at Marquis, link by link
Link 1 — Initial access: the SonicWall appliance
Per Marquis’s own notifications, attackers entered via the compromised SonicWall firewall on August 14, 2025. Whether the specific vector was CVE-2024-40766, default-group abuse, portal exposure, or credential compromise on the appliance is not publicly pinned — but all candidate vectors share one property: they were known and fixable before the attack. The 9.3-severity patch had existed for a year; SonicWall had explicitly urged password rotation and “user must change password” enforcement on locally managed SSLVPN accounts; Rapid7 had published the three-vector analysis.
Link 2 — VPN session as trusted identity
Once the appliance fell, the attacker inherited something better than credentials: a VPN session positioned inside the perimeter. Edge-device compromise collapses the entire outside-in trust model — the VPN whose whole job is to separate untrusted from trusted becomes the bridge. From there, movement proceeds with the privileges of the SSLVPN account(s) involved, especially if default groups had quietly granted broader access than intended.
Link 3 — Unsegmented multi-client data within reach
The stolen set — SSNs, taxpayer IDs, card data — indicates the intruder reached the client-data stores. There is no public indication that data was compartmentalized per client institution in a way that would have contained the blast radius to one bank’s slice. In a concentration vendor, the difference between “all 74 clients’ data in one zone” and “per-institution segmentation” is the difference between a 672,075-person breach and 74 separate small ones — with corresponding differences in who must notify, how many customers panic, and how many class actions file.
Link 4 — Mass exfiltration, unseen or unacted upon
However the data left, it left at scale. The investigation took until late October to scope what was taken — meaning the exfiltration itself wasn’t stopped in the act. Inside a vendor network holding twenty banks’ worth of PII, bulk egress to an unknown destination should be the single loudest alarm in the environment.
Link 5 — Downstream detonation
The final stage didn’t happen at Marquis at all: it happened at 74 banks and credit unions forced to discover, months later, the scope of an intrusion they couldn’t see, notify customers they’d never met about data they never held directly, and absorb the customer-service and litigation shock of a breach that technically didn’t happen to them. One vendor’s December becomes every client’s Q1.
How this attack could have been stopped — five break-points
Break-point 1: Treat edge devices as critical attack surface (kills Link 1)
The patch for CVE-2024-40766 shipped in August 2024 — a year before the attack. Edge-device hygiene is not routine server patching; it’s its own discipline:
- Edge asset inventory with owner + version + EOL tracking. You cannot patch what nobody owns. Appliances get dropped, inherited, forgotten.
- 72-hour patch SLA for internet-facing CVSS ≥ 8.0 — and assume KEV-listed edge flaws are being exploited the day the advisory drops, because they were (exploitation was observed “shortly after” the August 2024 advisory).
- Configuration hardening per vendor guidance: rotate all appliance-local and SSLVPN passwords, enforce “user must change password,” eliminate the SSLVPN Default Users Group risk, and restrict the Virtual Office Portal — the exact mitigations SonicWall and Rapid7 published publicly.
- Compensating monitoring: appliance login anomalies, configuration dumps, new admin sessions from unfamiliar geographies.
Break-point 2: Phishing-resistant MFA on every VPN account — no exceptions (kills Link 2)
An SSLVPN account without hardware-backed MFA is a perimeter credential on the public internet. All of them — vendor staff, client users, administrators — need phishing-resistant second factors. If session tokens or appliance accounts can’t support MFA, that’s an architecture decision to migrate, not a risk to accept.
Break-point 3: Per-client data segmentation inside the vendor (kills Link 3)
For any multi-tenant processor, segmentation is the containment story. The target state: compromise of one zone exposes one institution’s slice, not the lake.
- Logical isolation per client institution — separate credentials, separate keys, separate logging, so no internal identity is a universal reader.
- No universal service accounts spanning client datasets; scope every processing pipeline to its tenant.
- Client-side question: banks should contractually require (and audit for) per-tenant segmentation proofs. If your vendor can’t demonstrate it, you’ve outsourced your breach radius along with your compliance workflow.
Break-point 4: Egress detection tuned for multi-client data (kills Link 4)
Inside a data warehouse for hundreds of banks, “large volume of PII leaving toward an unknown destination” is the defining detection use case:
- UEBA on data movement per zone, per pipeline: baseline volumes and destinations, alert on deviation, and auto-block above thresholds.
- DLP pattern packs for the regulated data types the vendor actually holds (SSN, card numbers, taxpayer IDs) on all egress paths — not just email.
- Anomaly budget: assume the intruder already has a valid internal identity; design detections around what data moves where, not who logged in.
Break-point 5: Fourth-party risk as an architectural control, not a questionnaire (kills Link 5’s blast)
Every affected bank had passed some vendor-risk assessment on Marquis. Questionnaires didn’t stop this; architecture and contracts can blunt it:
- Map concentration: know which vendors sit on aggregated multi-institution data — the four- and fifth-party exposures regulators increasingly flag. (For a systematic method, see our threat-modeling approach to externally-exposed tooling — the same discovery-then-bound pattern applies to vendor perimeter services.)
- Contractual breach-notification SLAs measured in hours, with forensic-data-sharing clauses — 74 banks waited months to learn the scope of an intrusion they had to disclose.
- Data minimization at ingestion: does the marketing platform actually need full card numbers and SSNs? Every field not shipped to the vendor is a field that can’t leak from it. This is the cheapest breach-radius reduction available.
- Exit and isolation plans for concentration vendors — the ability to pull data and reroute processing when a vendor is burning.
The legal aftershock: lawsuits in every direction
The Marquis aftermath is a map of modern breach liability:
- 36+ consumer class actions against Marquis (per its own reporting) — consolidated harm from 672,075 individuals’ PII/card exposure.
- Marquis v. SonicWall: the fintech sued its own security vendor for gross negligence, tying the breach to the September 2025 MySonicWall/cloud-backup incident — the supply chain’s blame flowing one more level up the chain.
- Client banks’ exposure: institutions that never touched the compromised infrastructure still owed notifications, credit monitoring, customer service, and in several cases their own litigation defense. Their “breach” was entirely contractual and reputational.
- The unconfirmed ransom: if paid, it adds the OFAC/sanctions and disclosure-complexity layer that paid ransoms always bring.
The bigger structural story: breach liability no longer tracks who was attacked. It tracks who held the data and who owed the duties. The banks learned that their regulator-facing obligations ignited the day Marquis’s firewall fell — not the day they learned of it.
If your bank or credit union used Marquis: what the record shows
- Watch for the official letters — breach notifications came through client institutions, not leak-site downloads; treat any “verify your account” contact citing the breach with suspicion.
- SSN exposure means credit freeze territory: freezes at all three bureaus plus fraud alerts are the proportionate response to taxpayer-ID and card-number exposure.
- Card data exposure means watching statements and replacing any card that shows unauthorized activity — Marquis stated no evidence of misuse, but “no evidence yet” is a snapshot, not a guarantee.
- Hang up on unsolicited calls asking to “verify” PINs, routing numbers, or the very details (SSN tail, DOB) that leaked.
The transferable lessons
- Your vendor’s firewall is your firewall. When a concentration vendor’s edge device falls, 74 institutions’ data falls with it. Vendor perimeter posture deserves a line in your own threat model.
- Patch speed for edge devices is measured in days, not quarters. A CVSS 9.3 flaw, exploited in the wild within weeks of disclosure, had a fix available for a year. Attackers don’t wait for your maintenance window.
- Multi-tenant data lakes need tenant-level walls. Per-institution segmentation converts a sector-level event into a containable incident. Demand proof, not promises.
- Questionnaires don’t stop intrusions; architecture does. The affected banks had all “assessed” Marquis. The controls that would have helped — segmentation, MFA, egress detection — are architectural facts you can verify or demand contractually.
- Data minimization is breach minimization. Full card numbers and SSNs sitting in a marketing/compliance pipeline multiplied this incident’s severity by orders of magnitude. Ship the minimum field set, always.
- Notification clocks belong to the data holder’s clients too. The banks’ obligations were triggered by Marquis’s August, not their own December. Design your vendor program around that asymmetry.
FAQ
What was the Marquis data breach?
A supply-chain intrusion at Marquis, a Texas fintech providing CRM/marketing/compliance software to 700+ banks and credit unions. Attackers entered through a compromised SonicWall firewall on August 14, 2025, and stole personal and financial data — names, SSNs, dates of birth, addresses, taxpayer IDs, and financial account information including card numbers — ultimately confirmed to affect 672,075 individuals across 74 client institutions.
How did attackers get into Marquis?
Through the company’s SonicWall firewall. The exact vector wasn’t publicly pinned, but the surrounding campaign exploited CVE-2024-40766 (CVSS 9.3), the SSLVPN Default Users Group risk, and exposed Virtual Office Portals — all known, patched, and documented before the attack.
Was Akira responsible for the Marquis breach?
Not confirmed. Akira was initially suspected because it was aggressively exploiting SonicWall flaws in the same window, but it has been effectively exonerated, and no group has claimed the attack. The unconfirmed claim that Marquis paid a ransom comes from a since-removed credit-union notice.
How many people were affected by the Marquis breach?
The final figure reported to the Maine Attorney General in March 2026 was 672,075. Earlier estimates ran higher — roughly 780,000 from state filings in December 2025 and up to 1.6 million per Comparitech in February 2026 — likely due to overlapping customers across multiple affected institutions.
Could the Marquis breach have been prevented?
Yes — at any of five points: patching and hardening the edge appliance (the fix existed for a year), phishing-resistant MFA on all VPN accounts, per-client data segmentation inside the vendor, egress detection for bulk PII movement, and data minimization plus contractual isolation requirements imposed by client banks.
Conclusion: the perimeter you forgot you had
The Marquis breach will be remembered for its numbers — 672,075 people, 74 banks, 36+ class actions — but its teaching value is architectural: modern banking runs on a mesh of concentration vendors whose edge devices, VPN accounts, and multi-client data lakes form a hidden perimeter that no single bank’s SOC monitors. When that perimeter fails, the liability doesn’t stay with the vendor: it flows to everyone whose data was behind the door.
The defenses are known, available, and none of them exotic: patch edge devices like the crown jewels they are, put hardware-backed MFA on every VPN identity, segment multi-tenant data per client, alarm on bulk egress, and shrink what you hand vendors in the first place. The banks that internalize this will stop asking “how secure is our vendor?” and start asking “when our vendor burns, how small is our share of the fire?” — a question answered in architecture, contracts, and data minimization, long before an August afternoon when a firewall quietly falls.
For the companion case — a bank breach where the entry point wasn’t a vendor’s firewall but the bank’s own employee mailbox — see the Bank of Baroda attack analysis.
References
- SecurityWeek — Marquis Data Breach Affects 672,000 Individuals (Mar 19, 2026) — final count, ransom claim, SonicWall attribution
- SecurityWeek — Marquis Data Breach Impacts Over 780,000 People (Dec 4, 2025) — notification letters, data types, company statement
- SecurityWeek — Akira Ransomware Attacks Fuel Uptick in Exploitation of SonicWall Flaw (Sep 11, 2025) — CVE-2024-40766, three-vector analysis
- Rapid7 — Akira Ransomware Group Utilizing SonicWall Devices for Initial Access — SSLVPN Default Users Group, Virtual Office Portal vectors
- Maine AG filing — Marquis final notification (672,075)
- Comparitech — Software vendor serving 700 banks hacked — ransom-payment claim, 1.6M estimate
- BreachHistory — Marquis 672K ransomware breach — timeline consolidation, lawsuit count
- Internal: Bank of Baroda breach attack analysis — the identity-side companion case
- Internal: MCP security threat model and hardening guide — discovery-then-bound pattern for exposed tooling
- Internal: Penetration testing cost and pricing guide 2026
