Marquis Software Solutions, a provider of data analytics tools for financial institutions, has filed a lawsuit against cybersecurity vendor SonicWall, alleging that a security failure at SonicWall was the root cause of a ransomware attack against Marquis. The complaint, filed on February 25, 2026, claims that a 2025 breach of SonicWall's MySonicWall cloud service exposed sensitive configuration data for Marquis's firewall. This data, including unencrypted MFA scratch codes, was allegedly used by attackers to bypass security controls and execute a ransomware attack in August 2025. The attack caused significant disruption for 74 of Marquis's banking clients. This lawsuit represents a critical test of vendor liability in the context of supply chain security.
The lawsuit outlines a complex supply chain attack. The core allegation is that a vulnerability in SonicWall's systems led to the compromise of Marquis, one of its customers.
MySonicWall cloud backup service.Marquis accuses SonicWall of gross negligence for storing MFA scratch codes in an unencrypted format and for failing to notify them that their firewall's security posture had been compromised by the vendor's own breach.
This incident is a prime example of a Trusted Relationship attack (T1199), where an organization is compromised by exploiting its reliance on a third-party vendor. The key technical failures alleged in the lawsuit are:
The impact of this supply chain attack is multi-faceted and severe:
No specific technical IOCs related to the ransomware attack itself have been disclosed in the legal filings.
Platform Hardening (D3-PH).New details emerge on SonicWall API flaw, revealing attackers guessed serial numbers to download unauthenticated backups with plaintext MFA codes. Marquis now faces 36 class-action lawsuits.
Further details from the lawsuit against SonicWall reveal the alleged mechanism of the MySonicWall cloud backup service vulnerability. Attackers reportedly exploited a defective API by guessing predictable device serial numbers to download firewall configuration backup files without proper authentication. These backups are said to have contained highly sensitive information, including Multi-Factor Authentication (MFA) scratch codes and other credentials, in unencrypted, plaintext form. This allowed attackers to bypass security controls and deploy ransomware. Additionally, Marquis Software Solutions is now facing 36 separate class-action lawsuits as a direct result of the breach and subsequent ransomware attack.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats