All Breaches
August 14, 2025 Verified Sensitive Record Financial Technology

Marquis Software Solutions 2025 Data Breach

The Marquis Software Solutions 2025 data breach is a ransomware and data-theft incident in the network of a vendor providing marketing, analytics, and customer-relationship services to banks, credit unions, and mortgage lenders across the United States. Marquis detected suspicious activity on August 14, 2025, and its forensic investigation confirmed that an unauthorized party copied files from Marquis systems.

Regulatory notices published by March 2026 identified 672,075 affected people. The event involved customer data held at Marquis for at least 74 financial institutions, but the company and affected banks said the intrusion was limited to the Marquis environment and did not enter the institutions' internal systems. LeakData maintains one Marquis record for this shared-vendor event.

How Was the Incident Confirmed?

Marquis's notice filed with the Iowa Attorney General says the company detected suspicious network activity on August 14 and determined it was a ransomware attack. It engaged outside cybersecurity specialists and notified federal law enforcement. The investigation found that an unauthorized party accessed the network that day and may have acquired certain files.

The individual-notice template states more directly that affected files were copied and that Marquis determined on October 27 that the recipient's fields were included. This evidence confirms personal and financial data theft rather than only service disruption or possible access. No ransomware operation publicly took responsibility, so the record attributes the attack to no named actor.

672,075 People and 74 Organizations

Marquis initially submitted fragmented state and customer-directed notices; later filings showed a total of 672,075 affected people. This is not a count of bank systems that were attacked. It represents individuals whose personal information appeared in files supplied by Marquis customer organizations and stored in the vendor's environment.

Early public lists identified 74 banks, credit unions, and financial institutions. Because Marquis serves more than 700 financial organizations, its entire customer base cannot be treated as breach scope. Some researchers calculated higher possible totals from state registries, but LeakData retains the company-notice figure of 672,075 in pwnCount and totalRecords.

What Data Was Copied?

Depending on the person, the files could contain names, physical addresses, phone numbers, Social security numbers, Taxpayer identification numbers, dates of birth, and financial-account information. Marquis said financial-account information did not include security or access codes. Not every field is assumed to exist for every person; individual letters identify the applicable elements.

This combination creates substantial identity-theft, new-account fraud, tax-fraud, and targeted bank-phishing risk. PINs, passwords, one-time codes, and payment cards were not confirmed by the company and are not added as data classes. The record also avoids unsupported generalizations about employee notes or account balances.

Attack Path and Organizational Boundary

State notices characterized the event as ransomware, and later company statements said the Marquis network was entered through a SonicWall firewall. Marquis subsequently sued SonicWall with allegations concerning the related security event and product protections. LeakData records the confirmed network-entry context but does not treat a specific vulnerability, stolen credential, or threat group as a forensically established cause.

The affected customer banks' systems were not part of the incident. Data came from files those organizations supplied for processing in Marquis marketing and communications services. This distinction prevents the incorrect conclusion that 74 separate banks were hacked while showing how one third-party-provider incident created downstream impact across many institutional customers.

Marquis's Response

Marquis worked with specialists to contain the attack, secure its network, and identify affected clients and individuals. It began notifying business customers between October 27 and November 25 and, at their direction, handled individual and regulatory notifications. The company said it implemented additional security technologies and processes and contacted law enforcement.

Eligible recipients were offered credit monitoring and identity-protection services and advised to review account statements and credit reports. People whose notices include a Social Security or tax identifier may consider credit freezes or fraud alerts, verify unfamiliar transactions through a financial institution's official channel, and avoid unexpected links sent in a bank's name.

How to Interpret This LeakData Record

This record establishes unauthorized access and a ransomware attack in the Marquis network on August 14, 2025, copying of files received from customer organizations, and notices covering 672,075 people. The event affected customers of many financial institutions but does not establish compromise of those institutions' own networks. One technical incident is consolidated under one vendor record.

Verified data includes names, addresses, phone numbers, Social security numbers, taxpayer identifiers, dates of birth, and financial-account information without access codes. Marquis said it had no evidence of misuse when notices were filed; that does not negate the confirmed file copying. Actor identity, exact exploit, alleged ransom payment, and higher estimated person totals remain outside the record without sufficient primary evidence.

672.1 Thousand
Affected Accounts
7
Data Types
High
Severity
Yes
Verification

Exposed Data Types

7
Names
Physical addresses
Phone numbers
Social security numbers
Taxpayer identification numbers
Dates of birth
Financial account information without security or access codes

Additional Information

Added DateJuly 27, 2026
Breach DateAugust 14, 2025
Domaingomarquis.com
SourceRansomware attack and theft of customer files
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information