The Containment Era is here. →Explore

Executive Summary

In August 2025, Marquis Software Solutions, a fintech firm serving over 70 banks and credit unions, suffered a ransomware attack that compromised sensitive personal and financial data of more than 1.3 million individuals. The breach was attributed to a vulnerability in SonicWall's firewall backup service, which allowed attackers to access Marquis's internal network. Exposed information included names, addresses, Social Security numbers, and financial account details. This incident underscores the critical importance of securing third-party services and the potential cascading effects of supply chain vulnerabilities. (claimdepot.com)

The Marquis breach highlights the escalating risks associated with third-party service providers in the financial sector. As cyberattacks become more sophisticated and supply chain vulnerabilities more prevalent, organizations must adopt comprehensive security measures, including continuous monitoring and regular penetration testing, to safeguard sensitive data and maintain regulatory compliance.

Why This Matters Now

The Marquis Software breach underscores the urgent need for financial institutions to reassess their third-party risk management strategies. With cyberattacks becoming more sophisticated and supply chain vulnerabilities increasingly exploited, organizations must implement continuous monitoring and regular penetration testing to protect sensitive data and comply with evolving regulatory requirements.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The breach was caused by a vulnerability in SonicWall's firewall backup service, which allowed attackers to access Marquis's internal network and deploy ransomware.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF could have limited the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's initial unauthorized access may have been constrained by limiting exposure of critical services to only trusted entities.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges could have been limited by enforcing identity-aware access controls.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's lateral movement within the network could have been constrained by enforcing east-west traffic controls.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's ability to establish command and control channels may have been limited by monitoring and controlling outbound communications.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's data exfiltration efforts could have been constrained by enforcing strict egress policies.

Impact (Mitigations)

The attacker's ability to deploy ransomware and disrupt operations could have been limited by reducing their access to critical systems.

Impact at a Glance

Affected Business Functions

  • Customer Data Management
  • Financial Transactions Processing
  • Regulatory Compliance Reporting
Operational Disruption

Estimated downtime: 14 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Personal and financial information of over 672,000 individuals, including names, addresses, dates of birth, Social Security numbers, and financial account details.

Recommended Actions

  • Implement continuous monitoring and regular penetration testing to identify and remediate vulnerabilities promptly.
  • Enforce strict access controls and least privilege principles to limit the impact of compromised credentials.
  • Deploy network segmentation to restrict lateral movement within the network.
  • Establish robust data encryption practices to protect sensitive information both in transit and at rest.
  • Develop and regularly test incident response plans to ensure rapid containment and recovery from security incidents.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image