Marquis Ransomware Attack Exposes 400K US Bank Customers
Texas-based marketing and compliance fintech firm Marquis is notifying dozens of U.S. banks and credit unions that an August 14 ransomware attack compromised the sensitive personal and financial data of at least 400,000 customers.
The full scope of the security incident came to light this week after Marquis submitted official data breach notifications to several state regulators, confirming that the cyberattack involved ransomware.
Massive Breach Spans Multiple US States
As a specialized marketing and compliance provider, Marquis assists financial institutions in consolidating and analyzing consumer data. The company’s platform integrates massive volumes of sensitive consumer banking information, serving more than 700 banking and credit union customers nationwide.
State-mandated disclosure filings reviewed in Texas, Maine, Iowa, Massachusetts, and New Hampshire confirm that at least 400,000 individuals have been impacted so far. However, this figure is expected to grow as more states receive and process regulatory filings from the company.
Texas and Maine Among Hardest Hit
Texas residents bore the brunt of the breach, accounting for at least 354,000 of the compromised records. Meanwhile, Marquis disclosed in its notice to Maine’s attorney general that customers of the Maine State Credit Union made up the vast majority of affected individuals in that state, representing roughly one out of every nine people impacted statewide.
Highly Sensitive Financial Data Stolen
The threat actors managed to exfiltrate a treasure trove of highly confidential consumer data. According to Marquis, the stolen information includes full names, dates of birth, mailing addresses, Social Security numbers, and direct financial data such as bank account numbers, as well as debit and credit card details.
Vulnerability in Firewall Exploited by Hackers
Technical disclosures indicate that the attackers gained initial entry by exploiting a known vulnerability in Marquis’s SonicWall firewall. Although Marquis did not officially attribute the intrusion to a specific threat group, cybersecurity analysts noted that the Akira ransomware syndicate was actively executing mass-exploitation campaigns targeting SonicWall devices during that timeframe.
Marquis has not yet clarified the total number of individuals compromised across its entire network, nor has it disclosed whether it received a ransom demand or negotiated with the hackers.
