A single vulnerability in SonicWall’s SSL-VPN has triggered one of the wider financial-sector data breaches of 2026. Attackers used it to break into Marquis Software Solutions, a vendor that serves community banks and credit unions, and the fallout has now touched more than 70 institutions. If you bank at a small local credit union, this is worth five minutes of your attention.

What happened

Marquis Software Solutions provides technology to community banks and credit unions across the US. Attackers got into its network through a vulnerability in SonicWall firewalls that allows multifactor authentication to be bypassed when logging into the SSL-VPN. Once inside, the intrusion was traced to the Akira ransomware group, which security researchers have linked to an improper access-control flaw in SonicOS, the operating system that runs SonicWall’s firewall appliances.

That single point of entry cascaded outward. Because Marquis serves dozens of banks and credit unions as a shared vendor, one breach at the vendor level became a breach at every institution whose data passed through its systems. Data breach notifications filed in Iowa list at least 70 affected financial institutions. The two largest named so far are Gesa Credit Union, with 152,000 affected individuals, and iQ Credit Union, with 111,000. Combined with the rest of the list, personal and financial data belonging to hundreds of thousands of consumers is now potentially exposed.

American Banker and TechRadar both broke down the scope of the incident as notifications rolled in.

The SonicWall and Akira angle

What makes this case a useful case study, beyond its size, is how ordinary the failure was. Akira didn’t need a zero-day exploit chain or months of custom tooling. It needed an SSL-VPN appliance with a known access-control weakness that let it slide past MFA, then normal credentials to move through the network from there.

This is the same pattern that shows up again and again in enterprise breach reports: an SSL-VPN appliance, the kind Cisco, SonicWall, and Fortinet sell to businesses for employee remote access, sitting on the public internet with a patch that hadn’t been applied yet. Our deep dive on why enterprise SSL-VPNs keep getting breached covers why this class of device is such a consistent target: it’s exposed by design, complex enough to have bugs, and disruptive to take offline for patching.

Industry breach data backs up how fast this specific vector has grown. Edge devices and VPNs jumped from roughly 3% to 22% of exploitation-driven breaches in a single year, a sevenfold increase. Legacy corporate VPNs were the entry point in the large majority of verified ransomware intrusions in 2025, up sharply from just a few years earlier. SonicWall, Cisco, and Fortinet SSL-VPN appliances remain, by a wide margin, one of the top ransomware attack vectors going into 2026.

Akira in particular has built a reputation for hunting exactly this kind of soft target. The group doesn’t need to breach a bank directly when a shared software vendor offers the same payoff with less resistance. One compromised appliance, one weak MFA implementation, and the group is inside a network that ultimately touches tens of thousands of downstream customers. That efficiency is precisely why edge devices have become the preferred entry point over phishing or credential stuffing, which take more effort per victim.

What made the SonicOS flaw so useful to Akira is that it undermined the exact control that’s supposed to stop this kind of intrusion in its tracks. MFA exists precisely so that a stolen or guessed password isn’t enough to get in. An access-control bug that lets an attacker route around that check turns a well-configured VPN gateway into an open door, without the appliance ever showing an obvious sign of compromise. Security teams monitoring for failed logins or brute-force attempts would have seen nothing unusual, because the flaw let attackers skip that step entirely rather than force their way through it.

Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.

Enterprise SSL-VPN versus your consumer VPN

It’s worth being precise about what actually broke here, because the word “VPN” is doing double duty in every headline about this story. Marquis was breached through an enterprise SSL-VPN appliance, the kind of hardware or software gateway that lets a company’s employees log into its internal network remotely. That’s a fundamentally different product from a consumer VPN service like NordVPN or Proton VPN, which routes your personal browsing traffic through an encrypted tunnel and doesn’t open a door into any internal corporate network at all.

Nothing about this breach implicates consumer VPN apps, and nobody’s personal VPN subscription had anything to do with it. If you’re weighing a consumer VPN for your own privacy, the risks that matter are logging practices, independent audits, and infrastructure design, not this story.

That said, the confusion is understandable, and it’s worth remembering that a “VPN” is only as strong as its weakest configuration setting. Enterprise SSL-VPNs fail because of unpatched software and improperly enforced MFA, the same basic hygiene issues that undermine security at any scale. If you manage IT for a small business, that’s the actionable lesson here: patch SonicWall and other SSL-VPN appliances as soon as updates ship, and confirm MFA is actually enforced on every VPN login path, not just configured and forgotten.

Why one vendor breach became 70 breaches

This incident is also a clean illustration of third-party vendor risk, a term that sounds abstract until you see it play out at this scale. Most community banks and credit unions are too small to run every piece of their technology in-house. They rely on shared vendors like Marquis for core software and services, which is efficient right up until that vendor gets breached. At that point, the blast radius isn’t one institution, it’s every institution the vendor touches.

That dynamic matters because it means the security of your bank account depends partly on decisions made by companies you’ve never heard of, using appliances you’ll never see. You can pick a bank with a strong reputation and still end up on a breach notification list because a vendor three steps removed from you had an unpatched firewall. That’s frustrating, but it’s also common enough that regulators increasingly expect financial institutions to audit their vendors’ security practices, not just their own.

Community banks and credit unions are particularly exposed to this pattern because they tend to rely more heavily on shared vendors than large national banks, which can afford to build and secure more of their own infrastructure. That’s not a knock on smaller institutions, it’s just an economic reality, and it’s exactly why breach lists like this one skew toward regional credit unions rather than the biggest names in banking. If anything, it’s a reason to expect more stories shaped like this one before the pattern gets fixed industry-wide.

A pattern that keeps repeating in 2026

Zoom out and this incident fits a shape that’s become familiar this year. A single unpatched edge device, whether it’s a SonicWall firewall, a Cisco appliance, or a Fortinet gateway, sits exposed at the perimeter of a network that was never meant to be the weak link. Attackers don’t need to out-clever a security team. They need one appliance that’s a few patch cycles behind, and one MFA setting that isn’t enforced the way it’s supposed to be.

What’s changed in 2026 is the scale of the fallout when that happens. Modern institutions, even small ones, rely on a web of shared vendors for core banking software, payment processing, and customer data management. A single compromised appliance at one of those vendors no longer means a contained incident. It means a breach notification mailed to everyone whose data ever touched that vendor’s systems, which is how a flaw in one company’s firewall becomes news for 70 different banks at once. Expect more stories with this shape before appliance vendors and their customers close the patching gap that keeps making it possible.

What to do if you bank at an affected institution

If your bank or credit union appears on the Iowa breach notification list, or if you’ve received a notice in the mail, treat it seriously even though you did nothing wrong. Your data was exposed because of a vendor’s unpatched appliance, not anything you did.

A few concrete steps: watch for the official breach notification letter and read what categories of data were involved. Consider placing a credit freeze with the major credit bureaus, which is free and stops most new-account fraud cold. Sign up for any free credit monitoring the institution offers, most breach notifications include it. And be alert for phishing emails or calls that reference the breach to sound legitimate, that’s a predictable follow-on scam after incidents like this one.

It’s also worth checking your statements over the next few months rather than just the next few weeks. Fraud tied to large breach dumps doesn’t always show up immediately. Attackers often sit on stolen data for a while, testing smaller institutions or waiting for the news cycle to move on before using it. A credit freeze protects you either way, since it blocks new accounts from being opened in your name regardless of when the data eventually gets used.

None of this is about your personal VPN setup. It’s about a vendor-side failure that happened to touch your bank. If you’re separately interested in tightening your own privacy setup, our guide on how to verify a VPN’s no-log claims is a good next read, and if you’re the type who wants a failsafe against connection drops, our kill switch explainer covers that layer of protection too.

Our Verdict

This breach is a vendor and enterprise-infrastructure story, not a consumer VPN story. A SonicWall SSL-VPN flaw let the Akira ransomware group into Marquis Software's network, and because Marquis serves dozens of community banks and credit unions, that single compromise now touches over 70 institutions and hundreds of thousands of consumers. If you bank at one of them, watch for the notification and consider a credit freeze. If you manage business IT, patch your SSL-VPN appliances and verify MFA is properly enforced. And if you're evaluating a personal VPN, know that this story has nothing to do with providers like NordVPN or Proton VPN, whose risk profile is about logging and audits, not corporate network exposure.