Marquis Accuses SonicWall of Security Lapses; Ties it to Ransomware Attack
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内。首先,我得仔细阅读文章,抓住主要信息。 文章讲的是金融科技公司Marquis起诉SonicWall,指控其防火墙服务的安全漏洞导致了勒索软件攻击。Marquis声称SonicWall的云备份服务在2025年的漏洞泄露了关键安全信息,黑客利用这些信息入侵了Marquis的网络,窃取了大量个人信息。 接下来,我需要提取关键点:Marquis起诉SonicWall,原因是安全漏洞导致的数据泄露和勒索攻击,影响了40万美国人。这些信息需要简洁明了地表达出来。 然后,我要确保语言流畅,避免使用复杂的词汇,并且控制在100字以内。可能的结构是先说明起诉的原因和结果,再提到受影响的人数。 最后检查一下是否符合用户的要求:不需要特定开头,直接描述内容。确保没有遗漏重要信息,并且用词准确。 </think> 金融科技公司Marquis起诉防火墙提供商SonicWall,指控其云备份服务的安全漏洞导致勒索软件攻击。黑客利用SonicWall的数据入侵Marquis网络,窃取大量个人信息。事件影响至少40万美国人。 2026-2-25 10:19:10 Author: thecyberexpress.com(查看原文) 阅读量:7 收藏

SonicWall

A legal dispute is intensifying in Texas as fintech firm Marquis sues its firewall provider, SonicWall, alleging that security failures within the company’s cloud backup service directly contributed to a far-reaching ransomware attack. 

The lawsuit, filed Monday in the U.S. District Court for the Eastern District of Texas, seeks a jury trial. Marquis claims that a 2025 breach at SonicWall “exposed critical security information for Marquis and every customer that used SonicWall’s firewall cloud backup service.”  

According to the complaint, hackers gained access to sensitive firewall configuration backup files, which were later used to infiltrate Marquis’ internal systems. 

The Alleged Bypass Through SonicWall 

Firewalls are designed to block unauthorized access to internal networks. However, Marquis contends that attackers exploited data stolen from SonicWall’s cloud backup service to understand precisely how customers configured their firewalls. That insight allegedly gave them a blueprint for breaching defenses. 

Among the information reportedly taken were emergency access credentials known as scratch codes. According to the complaint, these codes were intended for urgent administrative access and were used by attackers to bypass safeguards and enter Marquis’ network. 

“SonicWall allowed a threat actor to obtain the keys to bypass that line of defense and walk right into Marquis’s internal network, the very thing that SonicWall’s firewall was supposed to prevent,” the lawsuit states. 

report-ad-banner

Once inside, hackers allegedly deployed a ransomware attack that disrupted operations and extracted sensitive information. Marquis, which provides data visualization tools to hundreds of banks and credit unions, reported that the attackers accessed “personally identifiable information concerning customers of some of Marquis’s financial institution clients.” 

The stolen data includes names, dates of birth, postal addresses, and financial details such as bank account numbers, debit and credit card numbers. Social Security numbers were also compromised in the cyberattack. 

Scope of the Data Breach

SonicWall first disclosed a breach in mid-September 2025, initially stating that fewer than 5% of customer firewall configuration backup files had been exfiltrated from storage servers hosted on Amazon’s cloud and maintained by SonicWall. However, in October, the company revised its statement, acknowledging that every customer had their firewall backup files stolen in the incident. 

Marquis began notifying affected individuals in December 2025 that its network had been breached in August of that year. SonicWall has not disclosed when the attackers first gained access to its systems, leaving uncertainty about how long the vulnerability may have existed. 

In its complaint, Marquis alleges that a code change made in February 2025 to one of SonicWall’s APIs “created a vulnerability exploitable by threat actors.” According to the lawsuit, this flaw allowed hackers to access customer firewall configuration backup files “without proper authentication” by guessing predictable firewall serial numbers. 

Marquis has not confirmed the total number of people affected. However, a listing with the Texas attorney general indicates that at least 400,000 individuals across the United States have been impacted. That figure is expected to increase as additional data breach notifications are filed with attorneys general in other states. 

The lawsuit now places SonicWall’s security practices for its cloud backup service under scrutiny. A jury in the Eastern District of Texas will ultimately determine whether the alleged vulnerabilities and subsequent ransomware attack stemmed from failures in SonicWall’s security controls, as Marquis claims. 


文章来源: https://thecyberexpress.com/marquis-sues-sonicwall-ransomware/
如有侵权请联系:admin#unsafe.sh