One of the largest cyberattacks in the financial services space has come to light again, as Marquis, a Texas-based fintech company, confirmed that more than 670,000 people were affected by a ransomware attack that occurred in August 2025. The incident was not limited to just a data leak, but also caused serious operational disruptions, affecting the operation of 74 banking institutions across the United States.

The company's profile and the scope of the attack
Marquis is a provider of digital marketing, data analytics, regulatory compliance and customer relationship management (CRM) services, serving more than 700 organizations in the banking and lending sectors. The nature of its services means it handles a huge amount of sensitive information, making it a particularly attractive target for cybercriminals.
See also: CISA recommends strengthening endpoint management after Stryker attack
According to official notifications to US authorities, the attackers managed to gain access to the company's systems by exploiting a vulnerability in a SonicWall firewall. From there, they infiltrated the internal network and proceeded to massively extract data.
The exposed data and the risks
The breach involved a wide range of personal and financial information. The data stolen included names, dates of birth, home addresses, phone numbers, social security numbers and tax information, as well as bank account information. Most worryingly, this data was not protected by additional layers of security, such as PINs or passwords.
Despite the severity of the breach, Marquis maintains that the attack was limited to its own systems and did not directly impact its customers' infrastructure. However, cybersecurity experts point out that such assurances do not negate the risk of secondary attacks, such as phishing or identity theft.

The link to the SonicWall vulnerability
The company attributed the breach to a known security incident announced by SonicWall in September 2025. At that time, the cybersecurity company had warned of a possible leak of credentials and tokens through its cloud backup service, urging users to immediately restore their access details.
See also: Interlock Ransomware: Cisco FMC Zero-Day Exploit
The practical exploitation of this data appears to have paved the way for more widespread attacks. Research by Mandiant found evidence that a state-sponsored hacking group may be behind the incident , which raises the level of seriousness and geopolitical dimension of the case.
Marquis: Legal consequences and business impact
Marquis filed a lawsuit against SonicWall, accusing it of gross negligence and misleading statements about the security of its products. According to the company, the attack had far-reaching consequences, including the loss of customers, damage to its corporate reputation and a significant reduction in its business value.
At the same time, the company is facing more than 36 class action lawsuits from consumers seeking damages for the leak of their personal data. The financial burden of potential damages, combined with the costs of restoration and security enhancements, may affect the company's long-term viability.

What does this attack mean for the industry
The Marquis incident is another wake-up call for the financial sector, and especially for fintech companies that rely on third-party infrastructure providers. It highlights the importance of early notification, vulnerability management, and multi-layered security.
See also: Fancy Bear Hits Greece: Russian Espionage Breaches the Hellenic National Defense General Staff
In an era where data is the most valuable asset, protecting it is not merely a technical issue but a critical trust factor. This case shows that even the most specialized companies are not invulnerable and that the consequences of a breach can extend far beyond the initial entry point.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: www.bleepingcomputer.com
