Find notable cyber news and cases, enriched with sources, timelines, and signals.
Data Leak Incident ×2

SonicWall cloud backup theft and Marquis downstream intrusion

Updated 03.06.2026 17:02
Case score 61
Members 3 First seen 18.09.2025 17:12 Latest activity 03.06.2026 17:02

Overview

**SonicWall**'s **MySonicWall** cloud backup service was breached, exposing firewall configuration backup files that contained encrypted credentials and configuration data. SonicWall said the access was limited to a specific cloud environment and API call, and later said a state-sponsored threat actor was behind the theft. The stolen files created follow-on risk because they could help attackers understand and target customer firewalls. Marquis Software Solutions later said its August 14, 2025 ransomware attack came through a SonicWall firewall and was tied to configuration data taken from the cloud-backup breach. SonicWall completed its investigation with Mandiant and told customers to reset credentials and review backups, while Marquis said its notifications covered 74 U.S. banks and credit unions and more than 400,000 people.
Latest development Open development history 3 earlier developments Marquis discloses 672,075-person data theft and 74-bank disruption Marquis, a Texas-based financial services provider, disclosed that a ransomware gang stole personal and financial data from 672,075 people after an August 14, 2025 attack on a compromised SonicWall firewall, and the incident disrupted operations at 74 banks across the United States; breach notifications were filed in early December, and affected files were reviewed on December 10, 2025.
  1. Earlier development

    Marquis Software Solutions hit by ransomware attack

    In **August 2025**, **Marquis Software Solutions** suffered a **ransomware attack** that affected its systems and downstream bank and credit union customers. The event was later linked to **firewall configuration data** stolen through **SonicWall's MySonicWall portal**.

  2. Earlier development

    SonicWall says all cloud backup customers were affected

    SonicWall said an unauthorized party accessed firewall configuration backup files stored in MySonicWall accounts for all customers who used SonicWall's cloud backup service. The company completed its investigation with Mandiant and said the exposed .EXP files contain AES-256-encrypted credentials and configuration data that could make firewall exploitation significantly easier.

  3. Earlier development

    SonicWall discloses cloud backup breach affecting MySonicWall accounts

    SonicWall said it recently detected suspicious activity targeting the cloud backup service for firewalls and that unknown threat actors accessed backup firewall preference files stored in the cloud for less than 5% of its customers. The company said the files contained encrypted credentials and other information that could help attackers exploit related firewalls, urged customers to reset credentials and review cloud backups, and recommended containment steps such as limiting WAN access, disabling HTTP/HTTPS/SSH management, turning off SSL VPN and IPSec VPN access, resetting passwords and TOTPs saved on the firewall, and reviewing logs and recent configuration changes. SonicWall said it was not aware of any files being leaked online, said the event was not a ransomware attack on its network, and described the access as a series of brute-force attacks.

Signals

Impact signals
Exploitation
Affected impact
CVEs/products
Geographic context
Status
Threat context
Data exposure

Threat actor context

1 listed

Malware & tooling context

3 families · 3 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Data Leak SonicWall MySonicWall cloud backup breach exposing firewall backup files
Updated 29.01.2026 19:57 Lead Contribution 55
Exploit No Known Public Exploit Data Type Authentication Tokens Data Type Corporate Secrets Data Status Partially Leaked

**SonicWall** said a **state-sponsored threat actor** stole **firewall configuration backup files** from its **MySonicWall cloud backup service** in a **September** security breach. The exposed **.EXP** backups contained **AES-256-encrypted credentials** and configuration data, and SonicWall said the incident was isolated to an **API call** in a specific cloud environment. The company completed its investigation with **Mandiant**, notified impacted customers and partners, and said the breach was **unrelated to Akira ransomware** and did **not impact SonicWall products or firmware**.

Incident Marquis Software Solutions hit by ransomware attack
Updated 29.01.2026 19:57 Scoring Support Contribution 4
Extortion Ransomware Encryption Incident Disclosed

**Marquis Software Solutions** disclosed that its **August 14, 2025** ransomware attack exposed personal data tied to **74 U.S. banks and credit unions** and affected **over 400,000 customers**. The company says attackers breached its network through a **SonicWall firewall** and stole files containing information received from business customers. Marquis says there is **no evidence of misuse or publication** of the data at this time. The incident remains centered on a victim-focused breach of a financial software provider and the downstream impact on its banking and credit union customers.

Incident SonicWall hit by network compromise
Updated 18.09.2025 17:12 Scoring Support Contribution 2
Extortion None Incident Disclosed

**SonicWall** said a **state-sponsored threat actor** was behind the **September** compromise of its **MySonicWall cloud backup service**, where firewall configuration backup files were stolen. SonicWall said the activity was **isolated to an API call** against a specific cloud environment, and that the stolen files contained **encrypted credentials and configuration data** that could help attackers launch targeted attacks against related firewalls. The company said the incident was **not linked to Akira ransomware**, did **not impact SonicWall products or firmware**, and Mandiant completed the investigation.