HomeIntelligenceBrief
🔓 BREACH BRIEF🔴 Critical🔓 Breach

Bank Software Vendor Marquis Exposes 672K Customers' PII in August Data Breach

Marquis Software, a banking‑software vendor, suffered an August breach that exposed personal and financial data of over 670,000 individuals. The breach was confirmed through regulatory filings and state breach registries, highlighting significant third‑party risk for financial institutions that rely on the platform.

🛡️ LiveThreat™ Intelligence · 📅 March 18, 2026· 📰 therecord.media
🔴
Severity
Critical
🔓
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
therecord.media

Bank Software Vendor Marquis Exposes 672K Customers' PII in August Data Breach

What Happened — In August, attackers infiltrated Marquis Software’s systems and copied files containing personal and financial data of 672,075 individuals. The breach was discovered on August 14, reported to law‑enforcement, and later confirmed through multiple state breach registries.

Why It Matters for TPRM

  • Sensitive PII (SSNs, TINs, DOB, account details) from banking customers was exfiltrated, raising identity‑theft and fraud risk.
  • The vendor services over 70 financial institutions; a breach can cascade to downstream partners and affect third‑party risk assessments.
  • Potential ransom payment hints at extortion tactics that may recur against similar SaaS providers.

Who Is Affected — Banks, credit unions, and other financial institutions using Marquis’s customer‑relationship software; their customers whose data was stored on the platform.

Recommended Actions

  • Review contracts and security clauses with Marquis Software or any similar banking SaaS providers.
  • Verify that affected institutions have performed forensic reviews and updated access controls.
  • Require evidence of post‑breach remediation (e.g., enhanced encryption, MFA, monitoring).

Technical Notes — Attack vector not publicly disclosed; hackers copied files from the vendor’s environment, suggesting possible credential compromise or insider access. No ransomware gang claimed responsibility, though a ransom payment was reportedly made. Exfiltrated data includes names, addresses, phone numbers, Social Security Numbers, Taxpayer Identification Numbers, dates of birth, and financial account information. Source: The Record

📰 Original Source
https://therecord.media/marquis-bank-vendor-data-breach

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

🛡️

Monitor Your Vendor Risk with LiveThreat™

Get automated breach alerts, security scorecards, and intelligence briefs when your vendors are compromised.