Marquis Software Solutions Sues SonicWall Over Ransomware Attack and Data Breach
Marquis Software Solutions has filed a lawsuit against SonicWall, alleging gross negligence and misrepresentation that led to a devastating ransomware attack on 74 U.S. banks. The breach, which occurred on August 14, 2025, exposed sensitive personal information from business partners, including names, addresses, phone numbers, Social Security numbers, Taxpayer Identification Numbers, and financial account details.
Marquis, a provider of data analytics, CRM tools, compliance reporting, and digital marketing services, serves a large clientele of over 700 banks, credit unions, and mortgage lenders. The attack, facilitated by a compromised SonicWall firewall, resulted in a significant data breach, highlighting the vulnerability of even well-protected systems.
Initially, Marquis blamed the breach on an unpatched flaw in SonicWall's firewall. However, further investigation revealed a more complex issue. The hackers exploited configuration data extracted from SonicWall's cloud backup infrastructure, which was vulnerable due to a security gap introduced in February 2025. This vulnerability allowed unauthorized access to AES-256 encrypted credentials, configuration data, and MFA scratch codes stored in SonicWall's cloud.
SonicWall's delayed disclosure of the incident, initially estimating only 5% of its customer base was affected, further exacerbated the situation. An investigation by Mandiant, an incident response company, confirmed that state-sponsored hackers were behind the attack. Despite Marquis's efforts to address the issue, SonicWall allegedly withheld critical information and ignored requests regarding the MFA bypass.
The lawsuit highlights the damages suffered by Marquis, including loss of customers, harm to its business reputation, lost business opportunities, revenue, and profit, as well as a substantial diminution in its enterprise value. Marquis is now defending over 36 consumer class action lawsuits stemming from the ransomware attack and seeks monetary damages, indemnification, contribution for related judgments, attorneys' fees, and equitable relief.
This case underscores the critical importance of cybersecurity and the potential consequences of negligence in the IT industry. As IT infrastructure becomes increasingly complex and fast-paced, organizations must prioritize robust security measures to protect sensitive data and maintain customer trust.