Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesA ransomware and data-security incident at Marquis Software Solutions, a third-party provider for financial institutions, may have exposed information belonging to approximately 51,000 Norway Savings Bank customers. The disclosure does not establish that 51,000 bank accounts were drained or that Norway Savings Bank’s online-banking systems were breached. It means customer information stored or handled in Marquis’s environment may have been accessible during the August 2025 incident.
What happened in the Marquis breach?
Marquis Software Solutions provides marketing, compliance, communications and customer-relationship tools to hundreds of U.S. banks and credit unions. Reporting describes a ransomware-related security incident in August 2025, with August 14 identified as a key date. Marquis investigated and notified law enforcement; financial institutions then reviewed which files held by the vendor could have been involved.
Norway Savings Bank, a Maine institution, later notified approximately 51,000 people that their information may have been exposed. The timing of a customer notice can differ from the date of an intrusion because the provider and each bank must determine which records were potentially accessible.
Why the 51,000 figure refers to Norway Savings Bank
The number is an institution-specific population, not a count of every person affected by the wider Marquis incident. Norway Savings Bank’s disclosure identified people whose information may have been present in files accessible during the vendor compromise. “Customers” or “individuals” is more precise than “bank clients,” because the figure does not mean 51,000 deposit accounts were accessed.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Other institutions have reported separate groups of potentially affected people. The figures below come from different disclosures and should not be added mechanically; definitions, dates and populations may differ.
| Institution | Reported potentially affected population |
|---|---|
| Norway Savings Bank | Approximately 51,000 people |
| Artisans’ Bank | 32,344 customers |
| VeraBank | 37,318 customers |
| CoVantage Credit Union | 160,000 people |
| 1st MidAmerica Credit Union | 131,070 people, according to a later update |
Comparitech reported that publicly disclosed figures had reached nearly 1.64 million people by February 2, 2026. Earlier reports cited lower totals, and later filings can change the count. These numbers are not directly comparable without reviewing each institution’s underlying notice. Comparitech’s reporting tracks the changing disclosures.
What information may have been exposed?
Reported categories for Norway Savings Bank customers included:
- Names
- Mailing addresses
- Dates of birth
- Social Security numbers
- Tax-identification numbers
- Financial-account information
Those categories may not apply to every person. Use the individual notice from your bank to determine exactly which data elements were involved. A notice saying information “may have been accessed” does not by itself prove that every listed record was copied, misused or published.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Was Norway Savings Bank’s online banking hacked?
Available reporting describes exposure in Marquis’s environment, not evidence that attackers entered and emptied Norway Savings Bank deposit accounts. At least some affected institutions said their own systems were not affected. Financial-account information held by a vendor is also different from online-banking credentials, passwords, multifactor-authentication codes or transaction authority.
The available reports reviewed for this article do not establish that customer funds were stolen. Exposed personal information can nevertheless make later phishing, impersonation, account takeover, tax fraud or new-account fraud more convincing. Continue monitoring accounts even if no suspicious transaction has appeared.
How a vendor breach can affect bank customers
- A bank uses an outside provider for services such as marketing, compliance or customer communications.
- Customer information is uploaded to, processed by or retained in the provider’s systems.
- Attackers compromise that provider’s environment, potentially making files from multiple institutions accessible.
- Each bank investigates its own records and sends notices to people whose information may be implicated.
This is technically different from a compromise of a bank’s core network, but it remains a bank-customer security issue. Banks are responsible for vendor oversight, contractual safeguards, incident response and clear communication.
What is known about the attack path?
Some secondary reporting and allegations in litigation connect the intrusion to a SonicWall firewall vulnerability. Those are allegations, not an adjudicated finding. The precise initial-access method should be treated as unconfirmed unless Marquis, investigators or court records establish it. The Lyon Firm’s account describes the litigation allegations.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Cybernews reported that Marquis appeared to have paid a ransom. That report should not be treated as an official confirmation. Even when a ransom is paid, there is no guarantee that stolen data is deleted or will not later be published. Cybernews’ coverage discusses the reported payment and affected institutions.
What affected customers should do now
1. Verify and preserve the notice
Use contact details in a letter or secure message you expected from the bank. Do not provide information to someone who calls or texts unexpectedly about the breach. Keep the notice because it may be required to enroll in services or dispute identity theft.
2. Use offered assistance carefully
If the notice offers credit monitoring or identity-restoration help, enroll only through the official instructions and note the deadline. Check whether the service is free for a stated period and whether it automatically renews as a paid subscription afterward.
3. Freeze your credit when sensitive identifiers were involved
If your notice confirms exposure of a Social Security number or tax-identification number, place a free freeze with Equifax, Experian and TransUnion. A freeze restricts access to your credit file until you lift it or provide a temporary thaw. It is different from a fraud alert, which asks lenders to take extra verification steps.
Recommended Free Tools
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
4. Check reports and existing accounts
Obtain reports through AnnualCreditReport.com, the federally authorized site. Look for unfamiliar accounts, inquiries, addresses and employers. Set transaction and login alerts at your bank, review statements and watch for new payees or unusual transfers.
5. Reduce takeover and phishing risk
Change passwords reused across email, banking or shopping accounts, beginning with email, and enable multifactor authentication. Treat messages claiming to be from Marquis or your bank as potential phishing, particularly when they request a password, one-time code, payment or remote access.
6. Report suspected identity theft
Contact the financial institution through a verified number, document fraudulent activity and report identity theft through the Federal Trade Commission’s recovery service. Contact law enforcement when appropriate.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Freeze, monitoring or paid identity protection?
| Option | What it helps with | Limits |
|---|---|---|
| Credit freeze | Blocks most new-credit applications using your credit file; generally free. | Does not stop phishing, existing-account takeover, debit-card fraud or tax fraud; must be lifted when you apply for credit. |
| Credit monitoring | Alerts you to some changes on credit files and may include restoration assistance. | Alerts after activity and does not prevent every type of fraud; breach offers may expire or auto-renew. |
| Identity-restoration or insurance service | May provide case management or reimbursement subject to terms. | Coverage limits and exclusions vary and do not reverse an exposed identifier. |
For many people, the free route—three bureau freezes, credit reports, bank alerts and FTC resources—is sufficient first-line protection. Paid services can be useful for broader alerts or hands-on restoration, but review renewal pricing, exclusions and insurance limits. Do not purchase a product promoted through an unsolicited breach-related message.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What remains uncertain
- The exact initial-access technique has not been conclusively established in the available reporting.
- There is no independently confirmed final nationwide victim total; disclosures continued to change.
- Reports do not establish that every listed data element was exposed for every individual.
- Public reporting does not establish that Norway Savings Bank customer funds were stolen or that exposed data was misused.
Why this incident matters beyond one bank
A provider serving more than 700 financial institutions creates concentration risk: one compromise can trigger investigations and notices across many otherwise separate banks and credit unions. The incident highlights why vendor due diligence, least-necessary data sharing, network segmentation, tested incident plans and prompt customer notification matter even when a bank’s own core systems remain operational.
Frequently Asked Questions
If my bank uses third-party software, am I automatically affected?
No. A bank’s use of outside vendors does not show that your information was involved in this incident. Check for a direct notice from your institution and follow its instructions.
Should I freeze my credit if I have not received a notice?
A freeze is free and can be placed proactively, but the decision depends on your circumstances. If you receive confirmation that a Social Security number or tax-identification number was involved, freezing all three credit files is a strong precaution.
The Bottom Line
The approximately 51,000 figure identifies a Norway Savings Bank customer group affected through Marquis Software Solutions, not 51,000 drained accounts or a confirmed total for the entire incident. Verify your notice, freeze your credit when sensitive identifiers were exposed, monitor existing accounts and remain alert for convincing follow-up scams.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




