SonicWall cloud backup theft and Marquis downstream intrusion
Case score 61
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 61
- Main story score
- 55
- Related evidence lift
- +6 / 20
- Contributing updates
- 2
- Context updates
- 0
- Data Leak Primary breach of MySonicWall cloud backup storage with exposed firewall configuration files. main
- Incident Downstream ransomware attack and banking-sector fallout tied to the stolen SonicWall configuration data. contributes
- Incident Earlier disclosure of the same cloud-backup theft and the API-based access path. contributes
Overview
Latest development Open development history Marquis discloses 672,075-person data theft and 74-bank disruption Marquis, a Texas-based financial services provider, disclosed that a ransomware gang stole personal and financial data from 672,075 people after an August 14, 2025 attack on a compromised SonicWall firewall, and the incident disrupted operations at 74 banks across the United States; breach notifications were filed in early December, and affected files were reviewed on December 10, 2025.
-
Marquis Software Solutions hit by ransomware attack
In **August 2025**, **Marquis Software Solutions** suffered a **ransomware attack** that affected its systems and downstream bank and credit union customers. The event was later linked to **firewall configuration data** stolen through **SonicWall's MySonicWall portal**.
-
SonicWall says all cloud backup customers were affected
SonicWall said an unauthorized party accessed firewall configuration backup files stored in MySonicWall accounts for all customers who used SonicWall's cloud backup service. The company completed its investigation with Mandiant and said the exposed .EXP files contain AES-256-encrypted credentials and configuration data that could make firewall exploitation significantly easier.
-
SonicWall discloses cloud backup breach affecting MySonicWall accounts
SonicWall said it recently detected suspicious activity targeting the cloud backup service for firewalls and that unknown threat actors accessed backup firewall preference files stored in the cloud for less than 5% of its customers. The company said the files contained encrypted credentials and other information that could help attackers exploit related firewalls, urged customers to reset credentials and review cloud backups, and recommended containment steps such as limiting WAN access, disabling HTTP/HTTPS/SSH management, turning off SSL VPN and IPSec VPN access, resetting passwords and TOTPs saved on the firewall, and reviewing logs and recent configuration changes. SonicWall said it was not aware of any files being leaked online, said the event was not a ransomware attack on its network, and described the access as a series of brute-force attacks.