Marquis Takes Legal Action Against SonicWall Over Ransomware Attack from Backup Breach
Marquis Software Solutions has initiated legal proceedings against SonicWall, alleging that a vulnerability in SonicWall’s cloud backup service resulted in a ransomware attack on its network.
Marquis Software Solutions has initiated legal proceedings against SonicWall, alleging that a vulnerability in SonicWall’s cloud backup service resulted in a ransomware attack on its network.
The lawsuit, filed in a Texas federal court, highlights deficiencies in securing sensitive firewall configuration files.
On Mon, Aug 14, 2025, Marquis experienced a ransomware attack. The attackers bypassed the company's defenses, protected by SonicWall firewalls with Multi-Factor Authentication (MFA) enabled.
Marquis's investigation revealed no unpatched vulnerabilities on local devices. Instead, the breach was traced back to SonicWall’s MySonicWall cloud infrastructure.
The lawsuit claims that SonicWall made a change to its Application Programming Interface (API) in Feb 2025. This change introduced a vulnerability, allowing unauthorized access to customer firewall backup files by predicting device serial numbers, without requiring authentication.
The lawsuit, filed in a Texas federal court, highlights deficiencies in securing sensitive firewall configuration files.
The exposed backup files contained sensitive network details, including unencrypted MFA scratch codes, usernames, SSL certificates, and local firewall passwords. The theft of these codes enabled attackers to bypass two-factor authentication defenses.
SonicWall allegedly failed to detect this breach for several months, identifying suspicious activity only in Sep 2025.
Marquis contends that SonicWall initially minimized the incident's severity, claiming it affected only 5% of firewalls. This led Marquis to believe its devices were secure. However, in Oct 2025, SonicWall disclosed that all customer backup files using the cloud service had been exposed.
As a result of the breach, Marquis faces over 30 consumer class action lawsuits and a commercial lawsuit for trade secret misappropriation. The company has also experienced lost business, contract terminations, and reputational damage within the banking sector.
Marquis accuses SonicWall of negligence, gross negligence, and unjust enrichment, seeking damages reimbursement.
The lawsuit asserts that SonicWall failed to adhere to industry best practices, particularly by leaving MFA scratch codes unencrypted, violating security guidelines from the National Institute of Standards and Technology (NIST) and the Cybersecurity and Infrastructure Security Agency (CISA). SonicWall's inadequate monitoring of its cloud network compromised the internal networks of businesses relying on its security solutions.
Based on reporting by GBHackers.
