Quick Summary
The Securityish Brief
Marquis Software Solutions experienced a ransomware attack in August 2025 that affected dozens of U.S. banks and credit unions. The company initially believed the attack stemmed from an unpatched SonicWall firewall, but later determined that the attackers exploited configuration data obtained from a breach of SonicWall’s MySonicWall online customer portal. SonicWall disclosed this breach on September 17, 2025, initially stating that it affected about 5% of its firewall customers using the cloud backup service.
However, further investigation revealed that all customers using the service were impacted. The breach allowed threat actors to extract access credentials and tokens, significantly increasing the risk of compromising customer firewalls. Marquis is currently evaluating its options regarding SonicWall, including potential recoupment of expenses related to the incident.
This incident underscores the importance of robust security measures and the risks associated with relying on third-party services for critical infrastructure. Organizations must remain vigilant about the security of their vendors and the potential implications of breaches that may not directly involve their systems.
Implications for Financial Institutions
Financial institutions, like those served by Marquis, should consider the risks posed by third-party vendors and ensure they have adequate security measures in place. The reliance on cloud services for data backup can introduce vulnerabilities that may be exploited by cybercriminals.
Organizations should regularly review their vendor security policies and ensure that they are informed about any breaches that could affect their operations. Additionally, implementing strong access controls and monitoring for unusual activity can help mitigate risks associated with third-party services.
As cyber threats continue to evolve, it is crucial for organizations to stay informed about the latest security incidents and adjust their strategies accordingly to protect sensitive data and maintain customer trust.
Key Takeaways
- Review your organization’s vendor security policies to ensure they address potential risks from third-party services.
- Implement strong access controls and regularly monitor for unusual activity in your systems.
- Stay informed about security incidents affecting your vendors and assess their impact on your operations.
- Consider conducting regular security assessments of your critical infrastructure and third-party services.
- Educate employees about the importance of cybersecurity and the risks associated with vendor relationships.
Key Terms & Concepts
- Ransomware: Ransomware is a type of malicious software that encrypts a victim’s data, demanding payment for its release.
- SonicWall: SonicWall is a cybersecurity company that provides firewall and security solutions for businesses.
- MySonicWall: MySonicWall is an online customer portal where SonicWall users can manage their accounts and services.
- Cloud Backup: Cloud backup refers to the process of storing data on remote servers accessed via the internet for recovery purposes.
- Configuration Data: Configuration data includes settings and parameters that define how a system operates, which can be targeted by attackers.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.