Company Details
marquis-software-solutions
314
2,981
52
gomarquis.com
0
MAR_1467200
In-progress

Marquis Company CyberSecurity Posture
gomarquis.comDedicated. Driven. Determined to excel. Marquis has a passion for performance and plays to win for over 700 banks and credit unions nationwide. We are experts in marketing and compliance customer data platforms (CDP) software, analytics, and solutions. We offer various products, including CRM, journey orchestration, conversational analytics, strategic consulting, cloud services, website design, and digital communication tools, all designed to give clients every advantage.
Company Details
marquis-software-solutions
314
2,981
52
gomarquis.com
0
MAR_1467200
In-progress
Between 0 and 549

Marquis Global Score (TPRM)XXXX

Description: Marquis Software Solutions, a Texas-based technology provider serving over 500 banks and credit unions, detected unauthorized network activity on **August 14, 2025**. A third-party breach investigation confirmed that an attacker accessed and exfiltrated sensitive files from its systems, exposing personally identifiable information (PII) of individuals associated with clients like CoVantage Credit Union. The compromised data included **names, addresses, phone numbers, Social Security numbers, financial account details, and dates of birth**—high-risk information for identity theft and financial fraud. Notifications to affected individuals began in **late October 2025**, with at least **22 New Hampshire residents confirmed impacted** as of November 26, 2025. While the breach was isolated to Marquis’ environment (sparing CoVantage’s internal systems), the scale of exposed data—particularly **SSNs and financial records**—poses severe risks of fraud, phishing, and long-term identity exploitation. Marquis offered **24 months of credit monitoring** via Epiq Privacy Solutions, but the incident underscores systemic vulnerabilities in third-party vendors handling sensitive financial data. Legal firms are pursuing class-action lawsuits for compensation, citing negligence in safeguarding consumer information.
Description: On August 14, 2025, Marquis Software Solutions—a technology vendor serving banks and credit unions—detected suspicious network activity, later confirmed as a **ransomware attack**. Despite paying a ransom, sensitive member data (including PII such as names, dates of birth, account numbers, and Social Security/Tax ID numbers) was exposed on the black market. The breach impacted **6,876 members**, including **6,511 Iowa residents**, with data dating prior to 2020. The exposure poses risks of **identity theft and financial fraud**, prompting notifications to affected individuals, law enforcement, and the Iowa Attorney General (November 7, 2025). Marquis offered complimentary identity protection services (credit/dark web monitoring, identity restoration) to mitigate harm. The incident underscores vulnerabilities in third-party vendor security, with long-term reputational and financial consequences for both Marquis and its client institutions, including **Community 1st Credit Union**.
Description: On August 14, 2025, a significant data breach involving Maine State Credit Union was discovered after Marquis Software Solutions Inc., a third-party digital and physical marketing vendor, detected suspicious activity on its network. The investigation revealed Marquis was the victim of a ransomware attack, with the unauthorized party gaining access to the network through its SonicWall firewall. This breach allowed the attacker to potentially acquire files containing sensitive information from Marquis’ systems. According to a disclosure filed with the Maine Attorney General’s office on Dec. 2, 2025, the Marquis cybersecurity incident impacted 38,334 Maine residents associated with Maine State Credit Union. The types of consumer information exposed included names, addresses, phone numbers, Social Security numbers, Taxpayer Identification Numbers, financial account information and dates of birth. This information is considered personally identifiable information (PII), and significantly raises the risk of identity theft and fraud for impacted individuals. Maine State Credit Union’s response After discovering the breach, Marquis promptly launched an investigation, engaged cybersecurity experts through legal counsel and notified federal law enforcement. Marquis then conducted a thorough review of the compromised files to determine the scope and nature of the data involved. By late October, Marquis began notifying affected business customers, including Maine State Credit Union,


Marquis has 163.16% more incidents than the average of same-industry companies with at least one recorded incident.
Marquis has 212.5% more incidents than the average of all companies with at least one recorded incident.
Marquis reported 2 incidents this year: 0 cyber attacks, 1 ransomware, 0 vulnerabilities, 1 data breaches, compared to industry peers with at least 1 incident.
Marquis cyber incidents detection timeline including parent company and subsidiaries

Dedicated. Driven. Determined to excel. Marquis has a passion for performance and plays to win for over 700 banks and credit unions nationwide. We are experts in marketing and compliance customer data platforms (CDP) software, analytics, and solutions. We offer various products, including CRM, journey orchestration, conversational analytics, strategic consulting, cloud services, website design, and digital communication tools, all designed to give clients every advantage.


Charles Schwab is a different kind of investment services firm – one that strives to disrupt the status quo of the traditional Wall Street approach on behalf of our clients. We believe today, as we did on Day 1, that when you find ways to improve the investing experience for your clients, then busin

In a changing world, we aim at anticipating transformation and driving your company for success. We are convinced to have the expertise and networks you need to develop your business. BNP Paribas Corporate and Institutional Banking is a leading global financial partner, offering you a wide range of

SMBC Group is a top-tier global financial group. Headquartered in Tokyo and with a 400-year history, SMBC Group offers a diverse range of financial services, including banking, leasing, securities, credit cards, and consumer finance. The Group has more than 150 offices and 86,000 employees worldwide

Capital Group was established in 1931 in Los Angeles, California, and now has 31 offices around the globe. For over 90 years we've provided carefully researched investment solutions and services to financial professionals. *** We've been made aware of an employment scam fraudulently using Capital G

MUFG (Mitsubishi UFJ Financial Group) is one of the world's leading financial groups. Headquartered in Tokyo and with over 360 years of history, MUFG has a global network with over 2,100 locations in more than 40 markets including the Americas, Europe, the Middle East and Africa, Asia and Oceania. T
At State Street, we partner with institutional investors all over the world to provide comprehensive financial services, including investment management, investment research and trading, and investment servicing. Whether you are an asset manager, asset owner, alternative asset manager, insurance com

At Fifth Third Bank, everything we do is rooted in our purpose: to improve the lives of our customers and the well-being of our communities. Since our founding in 1858, we’ve been committed to creating a better financial experience by empowering our customers and clients to achieve what matters most

We are born collaborative We believe that change is only possible when everyone works together for the same purpose, after all, cooperativism is in our DNA. Besides this, we know that as important as it is to provide affordable financial solutions it is just as important to value growing together,

As a brand with a legacy of over 160 years in Africa, we have a deep understanding and belief in the boundless opportunities that this continent presents. Our vision extends beyond mere geography; it encompasses a profound recognition of the potential for growth that resonates within our people, cus
.png)
Justin K. Bibee is a distinguished professional in the cybersecurity services industry.
Rami Al Idrissi is a highly accomplished engineer and a forward-thinking leader with extensive expertise in Operational Technology (OT) and...
Data breach at Marquis Software impacts 6876, exposing SSNs, account numbers, and more. Check if you're affected.
Rodney Julien is a distinguished professional in engineering operations and information security with AI, with eleven years of experience in...
John G. Keir, Esq., CISSP, CRISC, recognized as a partner and department managing attorney at Vernis & Bowling.
Mr. Kamal Sayeed is a distinguished professional with over 20 years of experience in the technology industry.
This article is part of BLG's 12-part series: 12 Strategic Priorities for Privacy, Cybersecurity, and AI Risk Management.
Mr. Fleurival currently serves as chief of network engineering at Science Applications International Corp., where he oversees research,...
As a senior technical security risk engineer at UCLA Health and a professor of information technology at the University of Redlands, Mr. Aasi...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Marquis is https://gomarquis.com.
According to Rankiteo, Marquis’s AI-generated cybersecurity score is 510, reflecting their Critical security posture.
According to Rankiteo, Marquis currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Marquis is not certified under SOC 2 Type 1.
According to Rankiteo, Marquis does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Marquis is not listed as GDPR compliant.
According to Rankiteo, Marquis does not currently maintain PCI DSS compliance.
According to Rankiteo, Marquis is not compliant with HIPAA regulations.
According to Rankiteo,Marquis is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Marquis operates primarily in the Financial Services industry.
Marquis employs approximately 314 people worldwide.
Marquis presently has no subsidiaries across any sectors.
Marquis’s official LinkedIn profile has approximately 2,981 followers.
Marquis is classified under the NAICS code 52, which corresponds to Finance and Insurance.
No, Marquis does not have a profile on Crunchbase.
Yes, Marquis maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/marquis-software-solutions.
As of December 03, 2025, Rankiteo reports that Marquis has experienced 3 cybersecurity incidents.
Marquis has an estimated 29,865 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include .
.png)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked with an empty string. Clearing a font family calls RelinquishMagickMemory on _drawInfo->font, freeing the font string but leaving _drawInfo->font pointing to freed memory while _drawInfo->family is set to that (now-invalid) pointer. Any later cleanup or reuse of _drawInfo->font re-frees or dereferences dangling memory. DestroyDrawInfo and other setters (Options::font, Image::font) assume _drawInfo->font remains valid, so destruction or subsequent updates trigger crashes or heap corruption. This vulnerability is fixed in 7.1.2-9 and 6.9.13-34.
FeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management. FeehiCMS version 2.1.1 allows authenticated remote attackers to upload files that the server later executes (or stores in an executable location) without sufficient validation, sanitization, or execution restrictions. An authenticated remote attacker can upload a crafted PHP file and cause the application or web server to execute it, resulting in remote code execution (RCE).
PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the admin/index.php endpoint. Specifically, the username parameter accepts unvalidated user input, which is then concatenated directly into a backend SQL query.
NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords. These hard-coded passwords could allow unauthorized access to both the application and database.
NMIS/BioDose V22.02 and previous versions' installation directory paths by default have insecure file permissions, which in certain deployment scenarios can enable users on client workstations to modify the program executables and libraries.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.