Technology
Data breach exposes 400,000 bank customers’ info
NEWYou can now listen to Fox News articles!
A major data breach tied to U.S. fintech firm Marquis is rippling through banks, credit unions and their customers. Hackers broke into Marquis systems by exploiting a known but unpatched vulnerability in a SonicWall firewall, gaining access to deeply sensitive consumer data.
At least 400,000 people are confirmed to be affected so far across multiple states. Texas has been hit the hardest with more than 354,000 residents affected. That number is expected to rise as additional breach notifications are filed.
Marquis operates as a marketing and compliance provider for financial institutions. The company says it serves more than 700 banks and credit unions nationwide. That role gives Marquis access to centralized pools of customer data, which also makes it a high-value target.
PASSWORD MANAGER FINED AFTER MAJOR DATA BREACH
Sign up for my FREE CyberGuy Report Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.
A major data breach tied to fintech firm Marquis exposed sensitive banking and identity data for hundreds of thousands of people. (Kurt “CyberGuy” Knutsson)
What information was stolen in the Marquis cyberattack
According to legally required disclosures filed in Texas, Maine, Iowa, Massachusetts and New Hampshire, hackers accessed a wide range of personal and financial data. Stolen information includes customer names, dates of birth, postal addresses, Social Security numbers and bank account, debit and credit card numbers. The breach dates back to Aug. 14, when attackers gained access through the SonicWall firewall vulnerability. Marquis later confirmed the incident was a ransomware attack.
While Marquis did not publicly name the attackers, the campaign has been widely linked to the Akira ransomware gang. Akira has previously targeted organizations running SonicWall appliances during large-scale exploitation waves. This was not a routine credential leak.
We reached out to Marquis for comment, and a company spokesperson provided CyberGuy with the following statement:
“In August, Marquis Marketing Services experienced a data security incident. Upon discovery, we immediately enacted our response protocols and proactively took the affected systems offline to protect our data and our customers’ information. We engaged leading third-party cybersecurity experts to conduct a comprehensive investigation and notified law enforcement.
“The incident was quickly contained, and our investigation was recently completed. It was determined that an unauthorized third party accessed certain non-public information within our network. However, there is no evidence indicating that any personal information has been used for identity theft or financial fraud. We have notified potentially affected individuals.
“We know our customers place great trust in us, and at Marquis, we take that responsibility seriously by making the protection of their information our highest priority. We are extremely appreciative of the cooperation, understanding, and support of our employees and customers during this time.”
HOW TO STOP IMPOSTOR BANK SCAMS BEFORE THEY DRAIN YOUR WALLET
Why the Marquis data breach creates long-term identity risk
When a data breach exposes your full identity, the danger does not disappear after the news cycle ends. Unlike a stolen password, this kind of information cannot be changed, which means the risk can stick around for a long time.
“With a typical credential leak, you reset passwords, rotate tokens and move on,” Ricardo Amper, CEO and Founder of Incode Technologies, a digital identity verification company, tells CyberGuy. “But core identity data is static. You cannot meaningfully change your date of birth or SSN, and once those are exposed, they can circulate on criminal markets for years. The breach is a moment in time, but the exposure it creates can follow people for the rest of their financial lives.”
That is why identity breaches are so dangerous. Criminals can reuse the same stolen data years later to open new accounts, build fake identities or run highly targeted scams that feel personal and convincing. Many attackers now combine this data with AI tools to scale their efforts. As a result, phishing emails, phone calls and even voice impersonations are harder to spot when they reference real details about your bank or account history.
The most likely scams after identity data is stolen
When criminals obtain verified identity data, fraud becomes targeted rather than opportunistic.
“Once criminals get their hands on rich, verified identity data, fraud stops being a guessing game and becomes a targeted execution,” Amper said.
The first major threat is account takeover. With enough personal details, attackers can bypass knowledge-based checks, reset passwords, change contact information and abuse accounts in ways that often look legitimate. The second risk is new account fraud. This includes credit cards, loans, buy now pay later services and even new bank accounts. High-quality data helps these applications pass automated systems and manual reviews.
The fastest-growing threat is synthetic identity fraud. Real data, like a Social Security number, is blended with fabricated details to create a new identity that matures over time before a large financial bust.
“These attacks are hard to catch early because the data being presented is accurate and often reused across multiple institutions,” Amper noted. “If your defenses can’t reliably tell a real human from an AI-generated impersonation, you are starting every decision from a position of disadvantage,” he added.
Why unpatched firewall flaws pose such a serious threat
Ransomware groups like Akira increasingly focus on widely deployed infrastructure to maximize impact. Firewalls sit at the boundary of trusted networks. When one is compromised, everything behind it becomes reachable.
“What we’re seeing with groups like Akira is a focus on maximizing impact by targeting widely used infrastructure. The strategy remains the same: Find a single weak point that gives access to many downstream victims at once,” Amper said.
This approach exposes a persistent blind spot in traditional cybersecurity thinking. Many organizations still assume traffic passing through a firewall is safe.
“When the perimeter device itself is the entry point, static defenses and outdated controls simply can’t keep up,” Amper explained.
Hackers accessed names, Social Security numbers and bank details by exploiting an unpatched firewall vulnerability. (Kurt “CyberGuy” Knutsson)
How long affected consumers should assume risk remains high
Identity data does not expire. Social Security numbers and birth dates stay the same for life.
“When core identity data reaches criminal markets, the risk does not fade quickly,” Amper emphasized. “Fraud rings treat stolen identity data like inventory. They hold it, bundle it, resell it and combine it with information from new breaches.”
Warning signs of misuse can be subtle. These include credit inquiries you did not authorize, account recovery alerts from unfamiliar services or phone calls that convincingly mimic a bank’s verification process using deepfake voice tools.
“The most damaging fraud often starts long after the breach is no longer in the news,” Amper added.
The overlooked impact of identity theft
Financial losses are only part of the damage. Victims often experience a lasting erosion of trust.
Amper says, “The most overlooked consequence is the psychological toll of knowing that you can no longer trust who is contacting you. Deepfake impersonation turns every phone call, video message or urgent request into a potential attack.”
Ways to stay safe after the Marquis data breach
When a breach exposes Social Security numbers, bank details and birth dates, the risk does not end with a password reset. These steps focus on protections that reduce long-term identity misuse and help you detect fraud early.
1) Freeze your credit with all major bureaus
A credit freeze prevents criminals from opening new accounts in your name using stolen identity data. This is critical after the Marquis breach, where full identity profiles were exposed. Freezing credit does not affect your score and can be lifted temporarily when needed. Place a free credit freeze with Equifax, Experian and TransUnion online or by phone. Each bureau must be contacted separately. Once frozen, new credit cannot be opened unless you temporarily lift or remove the freeze using a PIN or account login.
2) Place a fraud alert on your credit file
A fraud alert tells lenders to take extra steps to verify your identity before approving credit. It adds protection if you are not ready to freeze credit everywhere or want an extra layer on top of a freeze. Fraud alerts last for one year and can be renewed. You only need to contact one credit bureau to place a fraud alert. Equifax, Experian or TransUnion will notify the others for you. Fraud alerts are free and last for one year.
3) Enable transaction and account alerts
Turn on alerts for withdrawal, purchase, login attempts and password changes across all financial accounts. Real-time alerts can help you catch account takeovers or unauthorized activity before serious damage occurs.
4) Review bank statements and credit reports regularly
Check statements and credit reports often, even months or years after the breach. Identity data from incidents like this is frequently reused later for delayed fraud. Watch for unfamiliar accounts, hard inquiries or small test charges.
5) Use phishing-resistant two-factor authentication
Text message codes can be intercepted or socially engineered. Where possible, switch to app-based or hardware-backed two-factor authentication. These options are harder for attackers to bypass, even when they know your personal details.
6) Rely on strong device-based biometrics where available
Biometrics tied to your physical device add a layer that criminals cannot easily replicate. Face and fingerprint authentication help block account takeovers driven by stolen identity data or AI-powered impersonation.
7) Use strong antivirus software
Reputable antivirus software helps detect malicious links, fake login pages and follow-up attacks that target breach victims. This adds protection against phishing and ransomware tied to identity-based scams.
The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.
Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.
THIRD-PARTY BREACH EXPOSES CHATGPT ACCOUNT DETAILS
8) Consider a data removal service
Data brokers collect and resell personal information that can be combined with breach data to fuel targeted fraud. A data removal service reduces how much of your personal information is publicly available and lowers your exposure over time.
While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.
Experts warn this type of identity exposure can fuel fraud and scams for years after the breach is discovered. (Kurt ‘CyberGuy’ Knutsson)
Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.
Get a free scan to find out if your personal information is already out on the web: Cyberguy.com.
9) Add an identity theft protection service
Identity theft services monitor credit files, dark web markets and account activity for signs that your stolen data is being misused. Many also offer recovery assistance in the event of fraud, which can save time and stress when dealing with banks, credit bureaus and government agencies. This monitoring is especially useful after breaches like Marquis, where identity data can resurface long after the initial incident.
See my tips and best picks on how to protect yourself from identity theft at Cyberguy.com.
10) Verify unexpected outreach through official channels
Be cautious of urgent calls, emails or texts that reference real banking or personal details. Scammers now use accurate breach data to sound legitimate. Hang up and contact your bank directly using the number on your card or official website.
11) Lock down tax and government accounts
Create or secure online accounts with the IRS, Social Security Administration and your state tax agency. Enable strong authentication and monitor for unexpected notices. Stolen identity data is often used for tax refund fraud or benefit scams long after a breach.
Kurt’s key takeaways
The Marquis data breach highlights how dangerous unpatched infrastructure vulnerabilities have become for the financial sector. When a single vendor holds data for hundreds of institutions, the fallout spreads quickly. For you, identity protection is no longer a one-time response. It is an ongoing necessity that can last years beyond the initial breach.
What questions do you still have about protecting your identity after a major data breach like this one? Let us know by writing to us at Cyberguy.com.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.
Copyright 2025 CyberGuy.com. All rights reserved.
Technology
Snap, YouTube, and TikTok settle suit over harm to students
Snap, YouTube, and TikTok have settled the first lawsuit of its kind, alleging that social media addiction has cost public schools massive amounts of money, according to Bloomberg. The suit, filed by the Breathitt County School District in Kentucky, claims that social media has disrupted learning and created a mental health crisis, straining budgets. The terms of the settlement have not been revealed yet, and Meta is still facing a trial in the same suit, which is viewed as a bellwether for over 1,000 similar lawsuits across the country
This follows an earlier case, settled by Snap and TikTok, in which a 19-year-old plaintiff claimed significant personal injury due to addictive social media apps. Google and Meta did not agree to a settlement in that suit, and it eventually went to trial, where a jury awarded the plaintiff $6 million. Meta also recently lost a suit brought by New Mexico’s Attorney General, to the tune of $375 million.
Beyond monetary awards, many, including New Mexico, are pushing for significant changes to social media apps to limit their harm to minors. And this is just the start of what’s shaping up to be a busy year for social media lawsuits. According to Bloomberg, lawyers representing school districts said their “focus remains on pursuing justice for the remaining 1,200 school districts who have filed cases.”
Technology
Missed voicemails with no calls? It could be a scam
NEWYou can now listen to Fox News articles!
It starts quietly. Your phone buzzes. You see a voicemail notification. But your phone never rang. Then it happens again. And again. Before long, your voicemail inbox looks like it’s under attack.
That’s exactly what Mike from Westport, CT, is dealing with right now. He wrote to us saying,
“I am so upset. Every 20 to 30 minutes, I am getting voicemails, but what’s weird is my phone never rings. After blocking the number, it just rolls over to a new source number. When I go to play the message, there is no audio. Is this a scammer just trying to get me to call them back? Not sure what the endgame is here. What can I do to stop this from happening? I really appreciate your help.”
What he is describing is something we’re seeing more often. It may feel random, but there’s a clear pattern behind this voicemail scam and here’s what you need to know to stay safe.
RECEIVING UNEXPECTED INTERNATIONAL CALLS? WHAT YOU NEED TO KNOW
Silent voicemail scams can flood a phone with blank messages even when the device never rings. (Getty Images)
Sign up for my FREE CyberGuy Report
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
- Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
What the silent voicemail scam actually is
This tactic is often called a silent voicemail scam or ringless voicemail spam. Here’s how it works in plain terms:
- Scammers drop voicemail messages directly into your inbox
- Your phone never rings, so it feels strange and urgent
- The message is blank, garbled or extremely short
- The number changes constantly to avoid blocks
At first glance, it looks like a glitch. That confusion is the point.
What’s really happening behind the scenes
This pattern almost always points to automated robocall systems using caller ID spoofing, not real people manually calling you.
Here’s what’s likely happening:
- Automated dialing systems are repeatedly hitting your number
- They use spoofed or constantly changing caller IDs, which is why blocking one number doesn’t stop it
- Some calls connect briefly, then drop, leaving behind a silent or very short voicemail
- In some cases, the system is “pinging” your number to confirm it’s active
Once a number is confirmed as active, it can be shared across spam networks and used in future campaigns.
Why scammers leave empty voicemails
It seems pointless, but there’s a strategy behind it.
1) They want you to call back
Curiosity does the work for them. Many people return the call just to figure out what happened. When you call back, you may:
- Reach a premium-rate number that charges per minute
- Get routed into a scam call center
- Confirm your number is active and monitored
2) They test if your number is real
Even if you never call back, your voicemail confirms your number is in use. That makes it more valuable for future scams.
3) They try to bypass spam filters
Because your phone never rings, traditional call filters may not catch it. That lets more of these messages slip through.
Why do the numbers keep changing
You block one number, and another appears minutes later. That’s usually a sign of caller ID spoofing and number cycling. Scammers use software to falsify the number that shows up on your phone and rotate through large batches of numbers to stay ahead of blocks and spam filters. Some of those numbers may be completely fabricated, while others may belong to real people whose caller ID information is being misused. Many of those numbers are:
- Fake
- Reassigned or temporarily used
- Tied to real people who have no idea their number is being spoofed
Blocking a single number can still be worth doing, but it usually will not stop the campaign by itself because the caller can keep switching numbers.
GOOGLE SEARCH LED TO A COSTLY SCAM CALL
Scammers may use ringless voicemail spam and caller ID spoofing to test whether a phone number is active. (Getty Images)
Is your phone being hacked?
This is one of the first things many people worry about. In most cases, no. These silent voicemails are more likely to be part of a scam call or robocall campaign than a sign that your phone has been hacked. Scammers can use tactics such as caller ID spoofing and ringless voicemail to reach you without making the call feel normal.
The bigger risk isn’t your phone itself. It’s how the scam tries to get you to respond. Calling back, pressing prompts or engaging with the message can confirm that your number is active and may expose you to more scam attempts. The FTC specifically advises people to hang up or delete the voicemail and not call back unknown numbers.
How to stop silent voicemail scams
You don’t have to just put up with it. There are ways to reduce or stop these messages.
1) Do not call back unknown numbers
Even if it feels harmless, skip it. If it’s important, the caller will leave a real message.
2) Enable spam call filtering
On iPhone and Android, turn on built-in call filtering and silence unknown callers. This helps reduce future attempts.
How to enable spam call filtering
On iPhone (latest iOS)
Apple now gives you two strong options: Silence Unknown Callers and Call Screening.
Option 1: Silence unknown callers
- Open Settings
- Tap Apps
- Tap Phone
- Scroll down and turn on Unknown Callers
This sends calls from numbers not in your contacts straight to voicemail without ringing.
Option 2: Turn on Call Screening (recommended)
- Open Settings
- Tap Apps
- Tap Phone
- Scroll down and under Screen Unknown Callers, select Ask Reason for Calling
This feature prompts unknown callers to say who they are before your phone rings, which filters out many spam calls automatically.
Optional: Enable spam identification
- Go to Settings
- Tap Apps
- Tap Phone
- Tap Call Blocking & Identification
- Tap Business Call Identification
- Make sure it is set to ON
This allows your iPhone to show verified business names and logos for legitimate callers when available.
On Samsung
Samsung combines spam protection with AI call screening.
Settings and feature names may vary depending on your Samsung model, carrier and software version.
Option 1: Turn on spam protection
- Open the Phone app
- Tap the three-dot menu (top right)
- Tap Settings
- Tap Caller ID and spam protection
- Toggle it ON
This flags suspected spam calls before you answer.
Option 2: Block unknown callers
- Open the Phone app
- Tap the three-dot menu (top right)
- Tap Settings
- Tap Block numbers
- Turn on Block calls from unknown numbers
This stops hidden or unidentified numbers from ringing your phone.
Option 3: Enable Call Screen (best option)
- Open the Phone app
- Tap the three-dot menu (top right)
- Tap Settings
- Tap Bixby Text Call or just Text Call
- Toggle it ON
This lets your phone answer unknown calls with AI and show you what the caller says in real time.
One important reality check: Even with these turned on, some calls may still go to voicemail. That’s because voicemail is controlled by your carrier, not your phone.
HOW TO STOP SPAM MAIL, POLITICAL TEXTS AND EMAIL SPAM FOR GOOD
Unknown voicemail messages that contain no audio may be part of an automated robocall campaign. (Kurt “CyberGuy” Knutsson)
3) Use a call-blocking app
Apps can spot patterns faster than manual blocking and stop repeat offenders. Many of these apps can also identify known scam numbers and automatically block high-risk calls, helping reduce how often your phone gets hit.
4) Contact your carrier
Many carriers offer network-level spam blocking. Ask about tools that block ringless voicemail or robocalls.
5) Use a data removal service
If your number keeps getting hit, it may already be circulating on marketing lists or data broker sites. These data removal services scan for your personal information and help remove it from databases that scammers often tap into. Cutting down where your number appears can reduce how often you get targeted over time. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com
6) Report the activity
You can report unwanted calls and voicemails to the Federal Trade Commission at reportfraud.ftc.gov or by calling 1-877-FTC-HELP (1-877-382-4357). Reports help track and shut down large scam campaigns.
7) Protect your number going forward
Avoid posting your phone number publicly. The less exposure it has, the harder it is for scammers to target you.
8) Register your phone number on the National Do Not Call Registry at donotcall.gov/
This can help reduce telemarketing calls from legitimate businesses, but it unfortunately won’t stop scammers, illegal robocalls, or exempt organizations (like charities and political groups) from calling you. Scammers often ignore the registry and use tactics like number spoofing to bypass it. Want to know more about why your phone still won’t stop ringing and what you can do about it? Check out our article on the ‘Do Not Call’ list loophole.
Kurt’s key takeaways
Silent voicemails are designed to mess with your instincts. They rely on curiosity and confusion, not sophisticated hacking. The best move is simple. Don’t engage. Let them hit a dead end. Over time, that tells the system your number isn’t worth the effort.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
So here’s the real question: If scammers are counting on curiosity to hook you, how often do you think that instinct is working on other people right now? Let us know by writing to us at Cyberguy.com
Sign up for my FREE CyberGuy Report
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
- Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
Copyright 2026 CyberGuy.com. All rights reserved.
Technology
Xbox is now XBOX
Xbox just allcapsmaxxed: Meet XBOX. This isn’t a joke; Microsoft appears to be actually rebranding Xbox to XBOX. Asha Sharma, Xbox CEO, ran a poll on X earlier this week, asking fans whether Microsoft should use Xbox or XBOX. The results were in favor of XBOX, and the company has now renamed its X account.
Curiously, the Threads and Bluesky accounts for Xbox haven’t been renamed yet, but if Microsoft is going ahead with a rebranding then I expect those will change soon. I asked Microsoft to comment on this potential Xbox rebranding and the company simply referred me to Sharma’s post.
The use of all caps for Xbox is a return to original form, though. Microsoft’s first Xbox logo for its console was all caps, and the company has favored using similar capped versions for the Xbox 360, Xbox One, and Xbox Series X / S console logos.
The apparent rebranding comes just a few weeks after Sharma scrapped Microsoft Gaming and renamed Microsoft’s gaming division back to Xbox. It’s part of Sharma’s continued promise of a “return of Xbox,” which has involved fan-focused console updates, a new Xbox logo, Game Pass pricing changes, and lots more in recent weeks.
-
Ohio2 minutes agoOhio Highway Patrol investigating fatal head-on crash on U.S. Route 62
-
Oklahoma9 minutes agoOklahoma ‘Getting Gritty’ After SEC Tournament Loss
-
Oregon15 minutes agoRecall issued for organic ice cream sold in Oregon over metal concerns
-
Pennsylvania21 minutes agoSen. McCormick tours NSF-funded AI-powered biotech labs at Penn
-
Rhode Island27 minutes agoWhat to expect at Roger Wheeler and Misquamicut beaches this summer
-
South-Carolina33 minutes agoSouth Carolina lands commitment from big transfer portal offensive lineman
-
South Dakota39 minutes agoFact brief: Was an east-west split of Dakota Territory considered?
-
Tennessee45 minutes agoTennessee man arrested after kidnapping his two grandchildren