
Marquis Software Solutions Ransomware Attack Exposes 672,000 Individuals
A ransomware attack on fintech firm Marquis led to the theft of sensitive personal and financial data, impacting hundreds of thousands of individuals.
Signal context
First seen: Mar 1, 2026
Last updated: Jun 19, 2026
Status: Public signal
Key points
- Approximately 672,000 individuals impacted.
- Exposed data included Social Security numbers, account details, and contact information across multiple banks and credit unions.
Signal analysis
BetaThis analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.
Sector: Information
Likely country: Location not provided
Watch ransomware, endpoint compromise and business interruption exposure.
- Source type: outside the affected organization
Impact area: Availability
- 3 signals in the same sector
- 2 signals with the same likely impact area
- 1 signal linked to this organization/domain
External sources
Related signals
Grouped by why the signal is relevant.
Cl0p Ransomware Group Exploits Oracle E-Business Suite Zero-Day
The Cl0p ransomware group launched a large-scale extortion campaign by exploiting a zero-day vulnerability (possibly CVE-2025-61882) in Oracle's E-Business Suite (EBS). This led to critical data breaches for dozens of large corporations, with over 100 companies allegedly impacted. The exploitation activity was observed as early as August 9, 2025, weeks before a patch was available, and suspicious activity dated back to July 10, 2025. The threat actors exfiltrated a significant amount of data from impacted organizations and sent high-volume emails to executives demanding payment.
Ultrahuman Data Breach Exposes Customer Wellness Data
Wearable health-tech startup Ultrahuman confirmed a data breach where hackers accessed customer wellness data through credentials stolen from an employee's malware-infected laptop. Approximately 0.1% of its user base was affected.
Data Breach Hits Over 100 Dutch Hotels via Shared Booking Software
Hospecs, a Dutch hospitality services firm, confirmed a data breach affecting at least 100 Dutch hotels, with reports also coming from Belgium and Ireland. The breach exposed guests' contact details and reservation information, which criminals are using for phishing attacks.
Critical FortiClient EMS Flaws Actively Exploited to Deploy Credential Stealers
Threat actors are actively exploiting critical vulnerabilities in Fortinet FortiClient Endpoint Management Server (EMS), including CVE-2026-35616 and CVE-2026-21643. CVE-2026-35616, a critical security flaw, was actively exploited in the wild to deploy credential-stealing malware (EKZ Infostealer), prompting an emergency patch in April 2026. CVE-2026-21643 is also mentioned in active exploitation campaigns.
Oracle Cloud Authentication Data Breach by 'rose87168'
A threat actor identified as 'rose87168' claimed to have breached Oracle Cloud's federated Single Sign-On (SSO) login servers and exfiltrated approximately 6 million records, impacting over 140,000 tenants. The stolen data reportedly includes Java Key Store (JKS) files, encrypted SSO and LDAP passwords, and Enterprise Manager JPS keys. While Oracle initially denied a breach of its main Oracle Cloud Infrastructure (OCI) platform, it acknowledged a security incident involving two obsolete servers where usernames were accessed. Cybersecurity firms and independent researchers confirmed the validity of some data samples shared by the threat actor. The attacker was active since January 2025 and sought assistance to decrypt stolen data, demanding payments to prevent further exposure. CISA issued guidance on credential risks associated with a potential legacy Oracle cloud compromise.
