It was reported that maropost.com was hosting client records in an unsecured database. This website allegedly was loading maropost.com assets at the time of compromise as reported by https://publicwww.com/websites/maropost.com/ with the cipher snippet http://burn20.com/;8286706; action=\'http://app.maropost.com/accounts/102/forms/