Marketo is a criminal extortion group known for stealing data without file encryption and emailing leaks to competitors.
Analyst brief
Marketo is a criminal data-theft extortion group that steals and leaks victim data without encrypting files. It primarily targets corporate victims, applying aggressive pressure by emailing sample data packs to their competitors. Key TTPs include pure data exfiltration for double extortion, leveraging a public leak marketplace, and email-based victim shaming. Defenders should focus on early data exfiltration detection, DLP controls, and monitoring Marketo's active leak site.
marketo
crime
Marketo, launched in April 2021, is a data-theft extortion marketplace that steals and sells data to third parties or back to victims without encrypting files, applying aggressive pressure by emailing victims' competitors with sample data packs.
What is the main difference between Marketo and other ransomware groups?+
Marketo does not encrypt files; they rely solely on data theft and exfiltration, applying pressure by selling stolen data to third parties or offering it back to the victim.
What tactic does Marketo use to create additional pressure on victims?+
The group increases pressure by emailing sample data packs to the victims' competitors, causing additional shame and coercing payment.