The name of the well-known sportswear manufacturer Puma has appeared on the dark web marketplace “Marketo marketplace”. This particular site is known for leaking and selling stolen data belonging to companies. Recently, a post was made which published data supposedly belonging to the company Puma.
See also: iCloud Private Relay: Causes your original address to be leaked

The ad on the Marketo marketplace claims that 1GB of data has been stolen from the company, which is being put up for auction. Whoever pays the most money will gain access to the stolen data from the large sporting goods company.
The cybercriminals behind the “Marketo” marketplace claim to be operators of an organized “stolen data marketplace” and do not operate as a typical ransomware group that distributes malicious code to block a victim’s network and encrypt their data.
One of the key features of the “Marketo” site is auctions for stolen data, which create competition between individuals interested in acquiring data, including the victim (who wants to recover their data).

See also: Greek man accused by the US of selling data on the dark web
As of yesterday, there have been more than 157 threat actors attempting to purchase stolen data purportedly belonging to Puma on the dark web market.
It is said that some of the stolen files were published on Marketo and most of them contain source codes of internal management applications that may be connected to Puma's Product Management Portal.
This data, if it truly belongs to the sportswear company, could be used by cybercriminals to carry out more dangerous attacks on Puma.
See also: Data of millions of Android gaming app users exposed
Experts who have analyzed the code have found evidence that suggests data may have indeed been stolen as a result of a breach of a third-party software provider.
Source: Security Affairs
