Desk live·
ForensicPost
Breaches/Finance/File 25-0814

Marquis Software Compromise Reached Customers of at Least 74 Banks

A compromise at Marquis Software on 14 August 2025 reached data belonging to customers of at least 74 banks and credit unions. Entry was through a SonicWall vulnerability with a patch available since 2024.

Constructed geometry · not a chart of case data
TargetMarquis Software
ActorAkira
D. Kennedy12 min readConfidence: high3 sources reviewed

Marquis Software, which supplies data analytics and customer communication tooling to financial institutions, was compromised on 14 August 2025. Reporting puts the affected population at between roughly 400,000 and 1.35 million individuals across at least 74 banks and credit unions, with exposed fields including Social Security numbers, Taxpayer Identification Numbers and financial account details.

Entry was reported to be through a vulnerability in a SonicWall firewall, identified as CVE-2024-40766. Researchers have linked the intrusion to the Akira ransomware operation.

The Identifier Contains The Date

CVE-2024-40766 was assigned in 2024. The compromise was in August 2025. Whatever the precise interval, a patch existed and had existed for a meaningful period.

This is not the unpatchable-backlog argument this desk makes at 26-0405 and 26-0329, where the volume of known defects exceeds any organisation’s capacity to remediate. A perimeter firewall at a company holding the customer data of 74 financial institutions is not a long-tail asset competing for attention. It is the front door.

Every One Of Those Institutions Passed A Vendor Review

Financial institutions are among the most heavily regulated purchasers in any economy. Each of the 74 will have conducted third-party risk assessment on Marquis: questionnaires, attestations, contractual security schedules, probably an annual review.

Seventy-four independent due-diligence processes, all of them compliant, none of which established whether the vendor patched its perimeter. That is not 74 failures of diligence. It is one failure of the instrument — the corpus’s recurring finding that vendor assessment measures the existence of a control framework and not the operation of it, filed at 26-0611 and 26-0201.

The Affected Population Is Somebody Else’s Customers

Nobody in this dataset chose Marquis. They chose a bank or a credit union — frequently a small local institution selected precisely because it is small and local — and the identity data went to a shared analytics platform as a consequence of that choice.

The community credit union model consolidates behind the scenes because individual institutions cannot build analytics tooling alone. The customer sees a local brand; the data sits in a national estate.

How we reported this

Compiled from public reporting, listed below. The affected range is reported inconsistently across sources and we give the range rather than a single figure. The Akira attribution is a researcher assessment and is not established. Corrections: corrections@forensicpost.com.

Sources
  1. Marquis bank data breach exposes 672,000 in ransomware attackFox News
  2. The seven largest banking data breaches of 2025American Banker
  3. Top 5 banking data breaches of 2025Cybersecurity Insiders
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary