Skip to content
article

Why 670,000 People Had Their Data Stolen Through a Firewall Vendor

A single unpatched firewall flaw led to over 670,000 people having their data stolen, most of them in Texas. Here's the plain-English story and the lesson for your business.

July 30, 2026
4 min read
AstraLink Connect Team

Here is a number that should stop any Texas business owner in their tracks. More than 670,000 people had their names, birth dates, addresses, Social Security numbers, and bank account details stolen, and Texas residents made up the largest single group of victims. The way it happened is the part that matters most for your business, because it had nothing to do with a phishing email or an employee mistake. It happened because of an unpatched hole in a firewall.

The chain of events

A Texas-based company called Marquis Software Solutions provides marketing and data services to more than 700 banks and credit unions across the country. In August 2025, attackers got into Marquis’s network by exploiting a known vulnerability in a SonicWall firewall, one that already had a patch available. From there, they deployed ransomware and pulled out sensitive customer data belonging to dozens of banks and credit unions.

By the time state regulators had the full picture, more than 670,000 people were confirmed affected, with Texas residents accounting for the largest share of victims of any state. The stolen information included Social Security numbers, dates of birth, and financial account details, exactly the kind of data that fuels identity theft for years afterward.

The uncomfortable lesson here

This was not a sophisticated, unstoppable attack. It was a known weakness that had a fix available and was not applied in time. That is the story behind an enormous share of business breaches: not some genius hacker outsmarting the world, but a gap that everyone knew about and nobody closed fast enough.

For a small or medium business, this raises a question worth sitting with. If a company serving hundreds of banks could miss a patch window, who is watching your firewall? Most SMBs do not have a dedicated security team checking for vendor patches every week. The firewall gets installed once and, unless something visibly breaks, it is rarely touched again.

What this means for your business, even if you are nowhere near a bank

You do not need to handle banking data to be at risk here. Any business that stores customer names, payment information, or health records is a target for the same kind of attack. The pattern is always the same: find a piece of network hardware with a known, unpatched hole, and walk right through it.

A few honest questions worth asking:

  • When was the last time your firewall’s software was actually updated?

  • Does anyone track security advisories for the equipment protecting your network?

  • If a vulnerability was announced tomorrow, how long would it take before your business was covered?

Why “set it and forget it” is the real risk

Most small businesses do not choose to leave a firewall unpatched. It happens because nobody owns the job. This is exactly why managed network security exists as a category. You should not need to hire a full-time IT person just to keep your front door locked.

CONNECT is built so that updates and monitoring happen as part of the service, not as a chore that falls through the cracks. If you want to see what is actually running on your network right now, our team can walk through it with you at no cost. Take a look at our Verify assessment to get started, or visit the business page to see how CONNECT keeps this from happening in the first place.

See How CONNECT Protects Your Business →

Sources

Tags

data-breach ransomware texas firewall
Back to blog