# Marquis Servicer Breach: Cascade Across 700+ Financial Institutions

- **Artifact ID:** CHQ-EX-2026-008
- **Public record:** https://record.cybersecurityhq.com/exhibits/chq-ex-2026-008
- **Machine-record SHA-256:** `e1bc452816070bd416afcef119bb191ebd756e3c03bcd8c090f7a8b982e46f88`

## Complete structured record

```json
{
  "id": "CHQ-EX-2026-008",
  "title": "Marquis Servicer Breach: Cascade Across 700+ Financial Institutions",
  "subtitle": "Observed breach cascade from third-party financial institution servicer to 700+ client institutions via unpatched infrastructure vulnerability",
  "classification_notice": [
    "This document is published as a CHQ Exhibit. It records historical conditions, breach events, and industry practices as they existed during the periods described. This Exhibit records observed breach conditions, cascade mechanisms, and regulatory obligations as documented in public breach disclosures and state notification filings during the stated period.",
    "This document does not address present conditions and carries no current applicability. No evaluation of past practices is intended or implied.",
    "CHQ Exhibits are not superseded by later artifacts unless explicitly invalidated for factual error."
  ],
  "metadata": {
    "artifact_class": "EXHIBIT",
    "temporal_scope": "OPERATIONAL (2025-08 to 2026)",
    "authority_level": "NON-JUDGMENTAL",
    "reliance_status": "CONTEXT_ONLY",
    "update_policy": "ERRATA_ONLY",
    "temporal_start": "2025-08-01",
    "temporal_end": "2026-12-31"
  },
  "sections": [
    {
      "heading": "I. Factual Record",
      "content": [
        "Affected Entity: Marquis (financial institution servicer). Client Exposure: 700+ financial institutions served by Marquis. Initial Access Vector: Unpatched SonicWall firewall vulnerability exploited to access Marquis systems. Intrusion Date: August 2025.",
        "Data Categories Exposed: Names, addresses, dates of birth, Social Security numbers, bank account details, debit and credit card numbers. Geographic Concentration: Texas reported highest number of affected individuals. Additional disclosures filed in multiple other states.",
        "Attribution: Widely linked to Akira ransomware group. Marquis has not publicly confirmed attacker identity.",
        "Cascade Mechanism: Single servicer compromise propagated exposure to customers of 700+ client financial institutions that had no direct vulnerability. Client institutions bore disclosure obligations despite originating breach occurring at Marquis.",
        "Disclosure Structure: State-level breach notification filings by or on behalf of affected financial institutions. No single centralized disclosure event.",
        "Regulatory Frame: Financial institution clients subject to SEC Reg S-P (effective Dec 3, 2025 for large entities; June 3, 2026 for smaller entities): customer notification within 30 days, regardless of breach origin at service provider.",
        "Third-Party Accountability Condition: Client institutions bore customer notification and governance obligations despite Marquis as the breached entity. Accountability followed impact, not origin of access."
      ]
    },
    {
      "heading": "II. Failure Pattern",
      "content": [
        "A single unpatched vulnerability at a third-party servicer cascaded exposure across 700+ financial institutions and their customers. None of the client institutions had a direct vulnerability. All bore disclosure and governance obligations.",
        "The intrusion occurred in August 2025. Public disclosure and state notification filings followed in 2026. The gap between intrusion and disclosure reflects both investigation timelines and the complexity of determining which downstream institutions required notification.",
        "The accountability structure is consistent with the regulatory convergence documented in CHQ-P-2026-001: regulatory obligations attached to impact, not to origin of access. Financial institution clients were required to notify their customers regardless of Marquis as the point of compromise.",
        "This incident instantiates the N-th party SaaS waterfall condition identified in Q1 2026 financial institution threat analysis: 60% of financial sector breaches in 2026 originated from N-th party providers, cascading through servicer relationships to regulated institutions."
      ]
    },
    {
      "heading": "III. Referenced By",
      "content": [
        "CHQ-ED-2026-004 — Evidence Docket: Third-Party Access Constitutes Insider Access for Incident Accountability."
      ]
    }
  ],
  "closing_statement": "This Exhibit records historical conditions. It carries no present applicability. No evaluative judgment is made about any organization, vendor, security posture, or attribution conclusion.\n\nTemporal scope: intrusion August 2025, disclosure and notification filings 2026. Exhibit issuance date is March 14, 2026.\n\nAttribution to Akira ransomware group is widely reported but not confirmed by Marquis. This Exhibit records the attribution as reported, not as established fact.\n\nSource: Fox News breach reporting, state notification filing records. Marquis has not made a comprehensive public disclosure as of Exhibit issuance date.",
  "hash_scope": "Full exhibit content body",
  "hash_generated": "2026-03-14"
}
```
