2
Published signals
currently linked to this company
Company intelligence
marquissoftware.com
This company page brings together public reporting currently associated with Marquissoftware. It reflects signals published by Shadow Tier and should not be read as a complete incident history.
Company links
2
currently linked to this company
0
recent published signals
0
recent published signals
0
confidence classifications
July 22, 2026
most recent published signal
Explore related intelligence
Based on all published signals currently linked to Marquissoftware. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.
Company signals
Get our Quarterly Ransomware Report as a PDF March saw 90 publicly disclosed ransomware attacks, marking the second month this year in which incidents exceeded 90. Organizations in the United States accounted for 60% of all reported attacks, with smaller nations such as Andorra and Panama also included among the 24 countries impacted. Healthcare remained the most targeted sector with 18 attacks, followed by government and manufacturing with 14 and 12 incidents, respectively. In total, 30 ransomware groups were linked to publicly disclosed attacks, with Qilin leading activity with eight attacks. Keep reading to find our who made ransomware headlines in March. 1. DragonForce ransomware group claimed responsibility for an attack on the Getulio Vargas Foundation (FGV) , a leading educational institution in Brazil, involving unauthorized access and the exfiltration of approximately 1.52 TB of data, including sensitive information such as names, identification details, and banking data. FGV confirmed it experienced a security incident that temporarily disrupted some of its systems and acknowledged that data associated with the institution has appeared on the dark web. 2. A cyberattack disrupted the Denmark School District in Wisconsin, leaving it without internet access for five school days and forcing teachers and students to switch to paper-based workarounds. District officials did not disclose which systems were impacted or whether any data was compromised. The INC ransomware group claimed responsibility, stating it had stolen 707 GB of data and issuing a six-day deadline for negotiations. 3. Qilin claimed responsibility for a breach of LISI Group , listing the French industrial component supplier on its dark web leak site. The company, which supplies parts to Airbus and Boeing, confirmed it experienced a cyber incident but stated that its impact was limited in scope. Samples released by the attackers reportedly include screenshots of bank transfers, sales plans, business documents, bank account details, and other sensitive files. 4. Anubis ransomware group claimed responsibility for a cyberattack on AkzoNobel , a global paints and coatings manufacturer, involving a breach at one of its U.S. sites. The attackers reportedly exfiltrated around 170GB of data, including sensitive information such as employee details, passport scans, internal documents, and client agreements. AkzoNobel confirmed the incident, stating it was contained and limited in scope, while investigations and notifications to affected parties are ongoing. 5. Community Health Action of Staten Island has notified certain individuals of a cybersecurity incident that may have involved unauthorized access to, or theft of, sensitive data. The breach notice offered limited details, confirming only that information such as names, Social Security numbers, and other personal data may have been affected. The Genesis ransomware group claimed responsibility, stating it exfiltrated around 200,000 records, including sensitive personal and medical data. According to the group, this includes approximately 60,000 records from HIV-tested patient databases, along with HIPAA-protected information and employee data. 6. QualDerm Partners recently disclosed additional details surrounding a December 2025 cyberattack, confirming that more than 3.1 million individuals were affected. The breach involved unauthorized access to parts of its network and the exfiltration of highly sensitive data, including personal information, medical records, treatment details, and health insurance data. Notification efforts are now underway, with impacted individuals being informed of the potential exposure. No known ransomware group has claimed the attack. 7. West Virginia law firm Katz Kantor Stonestreet & Buckner (KKSB) disclosed a data breach involving potential exposure of sensitive personal information. According to a notice on its website, the firm detected suspicious activity on its network and initiated an investigation, which confirmed that data such as names, Social Security numbers, and driver’s license details had been accessed. The Kairos ransomware group claimed responsibility alleging it exfiltrated approximately 700 GB of data. 8. 12,655 individuals have been notified of a data breach stemming from an August 2025 incident involving the Children’s Council of San Francisco . The breach notice did not clarify whether any of the compromised data related to children. Two weeks after the attack, the SafePay cybercriminal group claimed responsibility via its leak site, demanding an undisclosed ransom within 24 hours in exchange for deleting the stolen data. It remains unclear whether the organization engaged with the attackers. 9. Nephrology Associates Medical Group has begun notifying patients of a cyberattack and data breach initially identified in May 2025. The organization detected suspicious activity on its network and took steps to secure its systems and limit further unauthorized access. An investigation later confirmed that a third party had accessed the network and exfiltrated files containing patient information, including names, medical and health data, as well as billing and payment details. 10. Valley Radiology Consultants Medical Group announced a security incident and data breach that was first identified in September 2025. Immediate action was taken to secure its network, and third-party cybersecurity experts were engaged to determine the nature and scope of the unauthorized activity. An investigation confirmed unauthorized access to its network and file containing patient information. 11. LHT Holdings recently detected a cybersecurity incident involving unauthorized access to parts of its network, which led to the encryption of certain systems. The company quickly isolated affected systems, engaged external cybersecurity specialists, and notified the relevant authorities. Preliminary findings suggest the incident was contained, with no evidence that personal or confidential data was accessed. However, the INC ransomware group claimed responsibility, publishing a number of documents on its leak site to support its claims. 12. Dutch plastic recycler Cabka identified a cybersecurity incident impacting portions of its IT systems. Upon detection, the company isolated affected systems and engaged external cybersecurity experts to carry out a forensic investigation, which remains ongoing. Play ransomware group claimed responsibility for the attack, issuing a four-day deadline for negotiations. 15. Qilin claimed to have breached Tennessee Valley Electric Cooperative (TVEC), based in Savannah, Tennessee. However, the group’s dark web post did not include details about the alleged attack or any data obtained, and no supporting evidence was provided. TVEC has not yet publicly responded to these claims.
Financial software provider Marquis Software Solutions experienced a ransomware attack on August 14, 2025, through a vulnerability in its SonicWall firewall. This breach led to the exfiltration of personal and financial information belonging to customers of over 74 US banks and credit unions. The stolen data included names, addresses, phone numbers, Social Security numbers, Taxpayer Identification Numbers, financial account information (without security or access codes), and dates of birth. The incident impacted an estimated 400,000 to over 800,000 individuals. Marquis began sending notifications to affected parties in early December 2025.
FAQ
It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Marquissoftware.
No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.
The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.