Ransomware Gang Stole Data of 672,000 People in 2025 Cyberattack on Marquis

Related

Nintendo Confirms Limited Employee Data Breach Linked to Third-Party Service

What happened Nintendo confirmed a security incident involving TinyPulse, a...

Novo Nordisk Reports Cybersecurity Breach Affecting Clinical Trial Patients

What happened Novo Nordisk disclosed a cybersecurity incident involving unauthorized...

HSE Fined €300,000 After Tullamore Hospital Data Breach

What happened Ireland’s Health Service Executive (HSE) has been fined...

Maine Closes Data Breach Portal After Fake Breach Notices

What happened Maine's Attorney General's Office has taken its public-facing...

Kodak Confirms Data Breach Claimed by ShinyHunters Extortion Gang

What happened Kodak has confirmed that an unauthorized third party...

Share

What happened

The Marquis ransomware incident involved attackers breaching the network of Marquis on August 14, 2025, gaining unauthorized access through a SonicWall firewall and stealing sensitive data from systems used to serve banking and credit union clients. The breach impacted data belonging to customers of dozens of financial institutions, with reports indicating that hundreds of thousands of individuals—over 672,000 people—were affected. Attackers accessed centralized customer data maintained by Marquis, including personal and financial information, and the incident was later confirmed to involve ransomware activity. The attack has also been described as a third-party supply chain incident, as Marquis provides services to multiple banks and credit unions, amplifying the scale of exposure. 

Who is affected

Customers of banks and credit unions that relied on Marquis Software Solutions are affected, particularly individuals whose personal and financial information was stored in systems managed by the vendor. 

Why CISOs should care

The incident highlights how ransomware attacks on third-party service providers can cascade across multiple organizations, exposing large volumes of customer data through a single point of compromise. 

3 practical actions

  1. Assess third-party risk exposure. Review vendors with access to customer or financial data for potential security gaps. 
  2. Audit firewall and network defenses. The attack path involved unauthorized access through a SonicWall firewall. 
  3. Monitor for data exposure after ransomware incidents. Stolen data may still circulate even after containment efforts. 

For more coverage of ransomware campaigns and extortion-driven attacks, explore our reporting under the Ransomware tag.

IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.