Desk live·
ForensicPost
Breaches/Accountability/File 25-1027

Discovered the Same Day, Told the Clients Ten Weeks Later

Marquis identified its breach on 14 August 2025 — the day it happened — and began notifying client financial institutions on 27 October. Those institutions then had to start their own clocks.

Constructed geometry · not a chart of case data
TargetMarquis client institutions
ActorAkira
S. Rosler11 min readConfidence: high2 sources reviewed

Marquis Software discovered its compromise on 14 August 2025, the same day it occurred, and began notifying its client financial institutions on 27 October — an interval of about 74 days.

Same-Day Detection Is Genuinely Good

It has to be said first, because this corpus is full of the alternative. Ten months at 26-0620. Five months at 25-0820. Breached in 2024 and disclosed in 2026 at 26-0515.

Marquis detected on day zero. Whatever else this file records, the detection capability worked, and it is worth being clear that the failure discussed below is a different failure.

The Clocks Run In Series

Breach notification law is written for a two-party world: an organisation holds your data, loses it, and tells you within a statutory window.

This incident has three parties. The vendor must determine scope and identify which client’s records were involved. Only then can the institution begin its own assessment — and its statutory clock generally starts when it learns, not when the vendor did. A customer of one of the 74 banks might therefore be notified months after the compromise while every party remains inside its legal window.

Nobody broke the rules. The rules simply have no term for the interval between a vendor knowing and a controller knowing, so the sum of two compliant timelines can be arbitrarily long. This desk filed the same structure at 26-0403 and 25-0710.

What The 74 Days Were Probably Spent On

In fairness, the work is real. Establishing which institution’s records were in which file, on a shared analytics platform, is a forensic exercise measured in weeks — and notifying prematurely with the wrong scope produces its own harm.

That is exactly why the gap is structural rather than culpable, and why it will recur in every vendor breach in this corpus. A rule requiring notice of the fact of a compromise on discovery, separate from notice of its scope, would close it. No regime this desk is aware of has one.

How we reported this

Compiled from public reporting of the Marquis incident, listed below, read against the notification structure it illustrates. The characterisation of what the interval was used for is our inference and is labelled as such. Corrections: corrections@forensicpost.com.

Sources
  1. The seven largest banking data breaches of 2025American Banker
  2. Marquis bank data breach exposes 672,000 in ransomware attackFox News
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary