Marquis A.I CyberSecurity Scoring
Marquis
Company Information
Website:https://gomarquis.com
Employees number:309
Number of followers:3,020
NAICS:52
Industry Type:Financial Services
Homepage:gomarquis.com
Marquis Risk Score (AI oriented)
Between 0 and 549
MarquisFinancial Services
Updated:
29/03/2026
29/03/2026
298/1000
Critical
C
Marquis Global Score (TPRM)
xxxx
MarquisFinancial Services
Score locked

MarquisCritical
Current Score
298C (CRITICAL)
01000
9 incidents
-91.75 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
331
JUNE 2026
322
MAY 2026
310
APRIL 2026
305
MARCH 2026
298
FEBRUARY 2026
312
Vulnerability
16 Feb 2026 • Marquis
SonicWall and Marquis Software Solutions: Texas-Based Financial Services Provider Marquis Cites SonicWall Breach for Ransomware Incident
Ransomware Attack on Marquis Software Solutions Disrupts U.S. Financial Institutions
285
CRITICAL-27
SONMAR1771316952
Ransomware Attack on Marquis Software Solutions Disrupts U.S. Financial Institutions
In August 2025, Texas-based Marquis Software Solutions confirmed a ransomware attack that rippled through multiple U.S. banks and credit unions, exposing vulnerabilities in the financial sector’s cybersecurity defenses. The breach, later linked to a security flaw in SonicWall’s systems reported in September 2025, underscored the risks posed by third-party vendor dependencies in critical infrastructure.
The attack compromised an unspecified number of financial institutions, jeopardizing sensitive customer and banking data. The incident highlighted the cascading impact of cyber threats, where a single breach in a software provider can disrupt operations across interconnected networks. Financial institutions, reliant on secure data management from vendors like Marquis, faced operational disruptions and potential reputational damage as a result.
Marquis Software Solutions traced the attack to vulnerabilities in SonicWall’s security controls, revealing how shared platforms can amplify risks for collaborative users. The breach prompted affected organizations to reassess their cybersecurity frameworks, with many implementing enhanced monitoring, threat assessments, and patch management to contain the fallout.
The incident serves as a case study in the evolving threat landscape, where ransomware attacks increasingly target supply chains to maximize disruption. As financial institutions evaluate preventive measures including zero-trust security models and regular audits the attack reinforces the need for proactive defenses against persistent cyber risks.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
284
DECEMBER 2025
363
Breach
01 Dec 2025 • Marquis
Marquis Software Solutions and Blaze Credit Union: Credit Union Members Notified of Massive Data Breach
Blaze Credit Union Data Breach via Third-Party Vendor
266
CRITICAL-97
MARBLA1767622189
Blaze Credit Union Members Impacted by Third-Party Data Breach Affecting 235,000
A data breach at Marquis Software Solutions, a third-party vendor serving financial institutions, has potentially exposed the personal information of over 235,000 members of Blaze Credit Union. The incident occurred at the vendor level, though details on the exact cause or timeline of the breach remain undisclosed.
Blaze Credit Union began notifying affected members via mailed letters in early December, offering complimentary credit monitoring and identity protection services through Marquis. While officials report no evidence of misuse or attempted misuse of the compromised data, they advise members to monitor accounts for suspicious activity, watch for phishing attempts, and review credit reports for unauthorized accounts.
Marquis Software Solutions provides services to multiple financial institutions, though the breach appears isolated to Blaze Credit Union’s member data. The credit union has not specified the types of information exposed but emphasizes proactive measures to mitigate risks for those impacted. Further updates may follow as investigations continue.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2025
363
OCTOBER 2025
444
Cyber Attack
01 Oct 2025 • Marquis
SonicWall
Coordinated Cyber Intrusions Targeting SonicWall SSL VPN Devices
346
CRITICAL-98
SON1232512101325
A sophisticated cyberattack campaign targeted SonicWall SSL VPN devices, compromising over 100 accounts since early October. Attackers exploited valid, exposed credentials (not brute-force) from a centralized IP (202.155.8.73), indicating a premeditated, highly coordinated operation. The breach aligns with SonicWall’s disclosure that unauthorized parties accessed encrypted firewall configuration backups (containing sensitive credentials) via the MySonicWall cloud platform, contradicting their earlier claim that only <5% of installations were affected.The attackers conducted reconnaissance, credential validation, and network scans, escalating to attempts at accessing local Windows accounts on compromised systems. While SonicWall denies a direct link between the backup leak and VPN intrusions, the timing and methodical approach suggest exploitation of stolen configurations. The risk includes catastrophic data loss, lateral movement, and further system compromise, prompting urgent remediation: credential resets, service disablement (HTTP/S, SSH, SSL VPN), MFA enforcement, and enhanced logging.The attack’s scale, precision, and potential for widespread exploitation—leveraging leaked configurations—poses a severe threat to global organizations relying on SonicWall’s infrastructure. Immediate action is critical to prevent further intrusions and mitigate damage.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2025
444
AUGUST 2025
499
Breach
14 Aug 2025 • Marquis
Marquis Software Solutions
CoVantage Credit Union and Marquis Software Solutions Data Breach
354
CRITICAL-145
MAR1463814112725
Marquis Software Solutions, a Texas-based technology provider serving over 500 banks and credit unions, detected unauthorized network activity on August 14, 2025. A third-party breach investigation confirmed that an attacker accessed and exfiltrated sensitive files from its systems, exposing personally identifiable information (PII) of individuals associated with clients like CoVantage Credit Union. The compromised data included names, addresses, phone numbers, Social Security numbers, financial account details, and dates of birth—high-risk information for identity theft and financial fraud. Notifications to affected individuals began in late October 2025, with at least 22 New Hampshire residents confirmed impacted as of November 26, 2025. While the breach was isolated to Marquis’ environment (sparing CoVantage’s internal systems), the scale of exposed data—particularly SSNs and financial records—poses severe risks of fraud, phishing, and long-term identity exploitation. Marquis offered 24 months of credit monitoring via Epiq Privacy Solutions, but the incident underscores systemic vulnerabilities in third-party vendors handling sensitive financial data. Legal firms are pursuing class-action lawsuits for compensation, citing negligence in safeguarding consumer information.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Breach
14 Aug 2025 • Marquis
CoVantage Credit Union
CoVantage Credit Union Data Breach via Third-Party Vendor Marquis Software Solutions
354
CRITICAL-145
COV4964449112725
On August 14, 2025, CoVantage Credit Union suffered a data breach via its third-party vendor, Marquis Software Solutions, which handles digital and physical marketing services. An unauthorized third party accessed Marquis’ systems, potentially acquiring sensitive personal information of members, including names, addresses, phone numbers, Social Security numbers, financial account details, and dates of birth. While the breach was confined to Marquis’ environment and did not compromise CoVantage’s internal systems, at least 22 individuals in New Hampshire were confirmed affected, with broader exposure likely across states like Wisconsin, Michigan, and Illinois. The breach was disclosed to authorities on November 26, 2025, following an investigation that began in September. Affected individuals were offered 24 months of credit monitoring, identity theft insurance ($1M), dark web monitoring, and restoration services through Epiq Privacy Solutions. The incident highlights risks tied to third-party vendor vulnerabilities, exposing customers to potential identity theft, financial fraud, and long-term reputational harm for the credit union. Vigilance via credit freezes and monitoring was strongly advised for impacted members.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2025
462
Vulnerability
01 Feb 2025 • Marquis
SonicWall and Marquis Software Solutions: Marquis Sues SonicWall, Alleges 2025 Cloud Flaw Led To Ransomware Hit / Fresh Today / CUToday.info
Marquis Software Solutions Sues SonicWall Over 2025 Cloud Vulnerability Linked to Ransomware Attack
457
CRITICAL-5
SONMAR1772202741
Marquis Software Solutions Sues SonicWall Over 2025 Cloud Vulnerability Linked to Ransomware Attack
Marquis Software Solutions has filed a lawsuit against SonicWall, alleging that a February 2025 cloud vulnerability enabled a ransomware attack in August 2025, exposing sensitive data from hundreds of financial institutions, including credit unions. The breach, which triggered widespread notifications across the credit-union system, has had significant fallout for affected organizations.
According to the complaint, the attacker exploited exposed credentials and firewall configuration data from SonicWall’s cloud incident, bypassing multifactor authentication (MFA) protections. Marquis claims SonicWall introduced an exploitable flaw through an API code change, allowing unauthorized downloads of firewall configuration backups. The company alleges that predictable device serial numbers and unencrypted MFA "scratch codes" in the backups enabled threat actors to compromise systems.
SonicWall has denied the allegations, stating it has not found technical evidence linking its cloud incident to the ransomware attack and plans to contest the claims. Meanwhile, Marquis, which serves over 700 banks and credit unions including Artisans’ Bank and VeraBank reported that the breach led to customer notifications, legal expenses, forensic costs, and class-action litigation. The company is seeking damages, arguing SonicWall failed to adequately protect customer firewall data.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2025
525
Breach
01 Jan 2025 • Marquis
Marquis Software Solutions: Union State Bank Data Breach Exposes Personal Information of Customers
Union State Bank Customers Impacted by Third-Party Data Breach at Marquis Software Solutions
455
CRITICAL-70
MAR1770198786
Union State Bank Customers Impacted by Third-Party Data Breach at Marquis Software Solutions
Union State Bank recently disclosed a data breach stemming from a security incident at Marquis Software Solutions, a third-party vendor that previously handled marketing and communications for the bank. The breach, which occurred in 2025, may have exposed personally identifiable information (PII) of some Union State Bank customers, including names and account details.
The incident was not isolated to Union State Bank multiple organizations using Marquis’ services were potentially affected. Notification letters were mailed to impacted individuals in January 2026, with Union State Bank also posting details on its website. Only a limited number of current and former customers, including those with closed accounts, were affected, and those who did not receive a letter are not believed to have been impacted.
While the exact cause and scope of the breach remain undisclosed, Marquis has offered 12 months of complimentary credit monitoring and identity theft protection through Epiq Privacy Solutions ID to affected individuals. Union State Bank has directed impacted customers to review their credit reports, monitor financial statements, and utilize the provided support services. Marquis has also established a dedicated assistance line for inquiries.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
AUGUST 2024
696
Ransomware
14 Aug 2024 • Marquis
Marquis Ransomware Attack Hits 400K+ Bank Customers
Ransomware Attack on Fintech Firm Marquis Exposes Data of 400,000+ Banking Customers
497
CRITICAL-199
MAR1764814193
The breach likely linked to the Akira ransomware gang that was targeting SonicWall customers during that timeframe
A ransomware attack on fintech firm Marquis has exposed the personal and financial data of at least 400,000 banking customers across dozens of U.S. banks and credit unions. The August breach, only now being disclosed through state filings, represents one of the year's most significant financial sector cyberattacks, with stolen data including Social Security numbers, bank accounts, and credit card information.
The financial services sector just got hit with another devastating blow. Texas-based fintech company Marquis is scrambling to notify dozens of U.S. banks and credit unions that their customer data was stolen in what's shaping up to be one of 2024's most damaging ransomware attacks.
The breach, which occurred on August 14, has already confirmed at least 400,000 victims across Iowa, Maine, Texas, Massachusetts, and New Hampshire - and that number is climbing as more state disclosures roll in. Marquis serves as a critical backend provider for over 700 banking and credit union customers, giving the company access to vast troves of consumer financial data.
Texas bore the brunt of the attack, with 354,000 state residents having their data compromised. But the geographic spread tells a more troubling story - this isn't just a regional incident. According to Maine's attorney general disclosure, Maine State Credit Union customers alone accounted for roughly one
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2020
756
Ransomware
16 Jun 2020 • Marquis
Marquis Software Solutions
Marquis Software Solutions Ransomware and Data Breach (2025)
598
CRITICAL-158
MAR4893548111825
On August 14, 2025, Marquis Software Solutions—a technology vendor serving banks and credit unions—detected suspicious network activity, later confirmed as a ransomware attack. Despite paying a ransom, sensitive member data (including PII such as names, dates of birth, account numbers, and Social Security/Tax ID numbers) was exposed on the black market. The breach impacted 6,876 members, including 6,511 Iowa residents, with data dating prior to 2020. The exposure poses risks of identity theft and financial fraud, prompting notifications to affected individuals, law enforcement, and the Iowa Attorney General (November 7, 2025). Marquis offered complimentary identity protection services (credit/dark web monitoring, identity restoration) to mitigate harm. The incident underscores vulnerabilities in third-party vendor security, with long-term reputational and financial consequences for both Marquis and its client institutions, including Community 1st Credit Union.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Marquis ??
What was Marquis's A.I Rankiteo Cyber Score in June 2026 ??
What was Marquis's A.I Rankiteo Cyber Score in May 2026 ??
What was Marquis's A.I Rankiteo Cyber Score in April 2026 ??
What was Marquis's A.I Rankiteo Cyber Score in March 2026 ??
What was Marquis's A.I Rankiteo Cyber Score in February 2026 ??
What was Marquis's A.I Rankiteo Cyber Score in January 2026 ??
What was Marquis's A.I Rankiteo Cyber Score in December 2025 ??
What was Marquis's A.I Rankiteo Cyber Score in November 2025 ??
What was Marquis's A.I Rankiteo Cyber Score in October 2025 ??
What was Marquis's A.I Rankiteo Cyber Score in September 2025 ??
What was Marquis's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on Marquis's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Marquis ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Marquis's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?