Skip to content
Lyon & Fiurex

Publicly Documented Security, Privacy & Legal Risk Findings

OSINT & Intelligence Vendors — Comparative Research Brief

Scope: Skopenow • Recorded Future • Social Links • Babel Street • Fivecast • Maltego • ShadowDragon • Apollo.io RECON is intentionally excluded from the adverse-vendor research scope.

L&F Research Desk

Research date: 15 September 2026 • 8 min read

Basis: publicly available sources, vendor disclosures, vulnerability databases, court records and civil-liberties research

Research framing. The user's phrase “dirty secrets” is operationalized here as documented adverse information: security incidents, product vulnerabilities, privacy and surveillance controversies, litigation, and other material public-risk signals. Allegations are identified as allegations; an authorized class action or filed lawsuit is not a finding of liability.

OSINT Vendor Risk Graphic
Figure 1. User-supplied OSINT & Intelligence Platforms comparative capability graphic.

Executive Summary

The strongest publicly documented adverse findings in this vendor set fall into four distinct categories: large-scale data exposure (Apollo), product vulnerability / dependency remediation (Maltego), third-party SaaS compromise (Recorded Future), and privacy / surveillance controversy (especially Babel Street, with Skopenow, ShadowDragon and Fivecast also appearing in public-sector monitoring contexts). [S1, S7, S13, S14, S15]

  • Apollo.io: 2018 exposure of 212M+ contact listings and ~9B data points; 2026 Québec privacy class action authorized; ongoing patent litigation with ZoomInfo. [S1, S2, S3]
  • Babel Street: Locate X has been documented as enabling highly granular location analysis; government use and civil-liberties concerns are well documented. [S5, S6, S7]
  • Maltego: CVE-2020-24656: XXE in versions before 4.2.12, NVD CVSS 6.5; 2026 release notes document remediation of critical/high-severity dependency vulnerabilities. [S13, S14]
  • Recorded Future: June 2026 Klue/Salesforce OAuth supply-chain incident exposed business CRM information; vendor states core intelligence systems and customer platform data were not compromised. [S15]
  • Others: Social Links disclosed one client-account compromise attributed to the client's environment; Skopenow, ShadowDragon and Fivecast show stronger public-risk signals around monitoring scope, government use and privacy than around published CVEs. [S8, S9, S11, S16, S19, S20, S21]

Methodology & Limitations

This report uses public sources available as of 15 September 2026, prioritizing primary vendor disclosures, NIST NVD, court/docket materials, government procurement records, and established journalism or civil-liberties research. The absence of a located CVE or breach should not be interpreted as proof that none exists. Search results are not exhaustive, and vendor security posture changes over time.

Monitoring policy: CTI and AML sources are rechecked every 15 days. Source changes, new reporting and unverified allegations are recorded for human editorial review; they are not automatically published as facts. Inaccessible sources remain explicitly unverified. Checks resume when the API service is running.

Comparative Findings Matrix

VendorSecurity incidentPrivacy / legal / surveillanceVulnerability signalSources
Apollo.ioConfirmed major data exposure (2018)Privacy class action authorized; patent litigationNo comparable current core-product CVE located[S1, S2, S3, S4]
Babel StreetNo vendor breach located in reviewed sourcesHigh-profile location-data / surveillance controversyNo vendor-specific public CVE located[S5, S6, S7]
SkopenowNo vendor breach located in reviewed sourcesLaw-enforcement monitoring use; Daniel's Law-related litigationNo attributable public CVE located[S8, S9, S10]
ShadowDragonNo vendor breach located in reviewed sourcesICE / DHS monitoring use and civil-liberties scrutinyNo clearly attributable public CVE located[S11, S12]
MaltegoNo major breach located in reviewed sourcesLimited controversy relative to peers in this reviewCVE-2020-24656; critical/high dependency fixes documented in 2026[S13, S14]
Recorded FutureThird-party Klue/Salesforce incident (2026)No comparable major privacy controversy locatedNo core-product CVE highlighted in this research[S15]
Social LinksSingle CrimeWall client account compromise disclosed (2025)Government/enterprise OSINT and sensitive data aggregation contextCVE-2025-25112 is unrelated and must not be attributed to this vendor[S16, S17, S18]
FivecastNo vendor breach located in reviewed sourcesNear-real-time collection, deleted-content retention, police/public-sector deploymentNo clearly attributable public CVE located[S19, S20, S21]

Note: “No CVE located” means none was identified in the reviewed public material; it is not a warranty of absence.

Detailed Vendor Risk Findings

Apollo.io / ZenLeads

Primary risk signal: Large historical data exposure + active privacy litigation

2018 data exposure

WIRED reported that a publicly accessible Apollo data trove contained more than 212 million contact listings and about 9 billion data points. The exposed material included publicly sourced professional data and private customer-imported information, including Salesforce-derived sales data. [S1]

2026 Québec privacy class action

In Badji c. Zenleads inc., the Superior Court of Québec authorized a class action over alleged collection, use, communication and commercialization of personal information without consent. The court’s authorization allows the claims to proceed; it is not a final finding of liability. Osler's 2026 review also notes leave to appeal. [S2]

Current data-broker model

Apollo's current privacy policy states that it operates as a registered B2B data broker and may make professional contact information such as names, email addresses, phone numbers, employment history and social-network URLs available to customers. Its U.S. state disclosure also describes categories that may be sold or shared, subject to applicable law. [S4, S22]

Patent litigation

ZoomInfo Technologies sued ZenLeads d/b/a Apollo.io in the U.S. District Court for the District of Delaware in 2025 alleging patent infringement. The docket remained active in 2026. Litigation allegations should not be presented as established misconduct. [S3]

Vulnerability / security assessment

No current Apollo core-product CVE comparable to Maltego's CVE-2020-24656 was identified in the reviewed sources. The most significant documented security event is the 2018 data exposure.

Defensible wording: “Apollo experienced a major 2018 data exposure involving 212M+ contact listings and ~9B data points; a Québec privacy class action concerning its data practices was authorized in 2026.” [S1, S2, S3, S4]

Babel Street

Primary risk signal: Location-data privacy and government-surveillance controversy

Locate X granularity

A 2024 NOTUS investigation reported that researchers using Babel Street's Locate X could follow device movement to sensitive locations and, when paired with people-search information, potentially identify supposedly anonymous devices. The reporting highlighted weak controls in the broader commercial location-data ecosystem. [S5]

Government use

VICE reported from a Secret Service contract that the agency purchased access to Babel Street's Locate X, a product based on location data generated by ordinary apps. The report framed the acquisition as part of the debate over government purchase of data that might otherwise require legal process. [S6]

Human-rights concerns

Amnesty International reported in 2025 that Babel X capabilities could support persistent, automated monitoring of migrants and others, based on reviewed public records and procurement/privacy documents. This is an advocacy organization's assessment, not a court finding. [S7]

Vulnerability / security assessment

No reliable vendor-specific Babel Street CVE was identified in the reviewed material. The dominant adverse-risk signal is privacy, surveillance scope and potential misuse rather than a published software exploit.

Defensible wording: “Babel Street has faced sustained scrutiny over Locate X and Babel X location / surveillance capabilities and government use.” [S5, S6, S7]

Skopenow

Primary risk signal: Law-enforcement monitoring and privacy litigation exposure

Monitoring capabilities

The Brennan Center summarized Skopenow as offering anonymous social-media data collection, behavioral recognition analysis, subject monitoring, automated alerts and visualizations combining location, consumer-report and social-media information. The report also documented law-enforcement demos/trials and government clients. [S8]

Daniel's Law-related litigation

Skopenow has been involved in litigation connected to New Jersey's Daniel's Law. In a 2026 filing, Skopenow stated that it does not maintain its own database, that its platform is not public, and that it serves vetted institutional clients; it disputed the plaintiffs' characterization and asserted good-faith compliance efforts. The existence of litigation is not proof of liability. [S9, S10]

Vulnerability / security assessment

No attributable public Skopenow CVE was identified in the reviewed sources.

Defensible wording: “Skopenow appears in public records concerning law-enforcement social-media monitoring and Daniel's Law-related privacy litigation; Skopenow disputes allegations and says it does not maintain a public database.” [S8, S9, S10]

ShadowDragon

Primary risk signal: Government surveillance scope and civil-liberties scrutiny

ICE / DHS procurement

The Brennan Center obtained contracts showing ICE purchased ShadowDragon SocialNet licenses and OI Monitor. The Center reported that the tools were intended to help analysts map online networks, aliases, associates and possible lifestyle/location inferences. [S11]

Vendor position

ShadowDragon's Trust Center says its products access only publicly available and lawfully accessible information and acknowledges public concerns about misuse and the broader implications of investigative technology. [S12]

Vulnerability / security assessment

No clearly attributable public ShadowDragon CVE was identified in the reviewed sources.

Defensible wording: “ShadowDragon's SocialNet and OI Monitor have been purchased by ICE; civil-liberties researchers have scrutinized the scope of social-media intelligence tools, while ShadowDragon says it limits itself to lawfully accessible public information.” [S11, S12]

Maltego

Primary risk signal: Documented product vulnerability + critical/high dependency remediation

CVE-2020-24656

NIST's National Vulnerability Database states that Maltego before version 4.2.12 allowed XML External Entity (XXE) attacks. NVD assigns CVSS v3.1 6.5 (Medium), with high confidentiality impact and user interaction required. [S13]

2026 dependency remediation

Maltego's 2026 Graph Desktop release notes document updates to Keycloak, Jackson, Guava and Bouncy Castle dependencies to remove critical and/or high-severity vulnerabilities. The release notes demonstrate active remediation; they do not by themselves show that every dependency issue was exploitable in Maltego's deployed context. [S14]

Attribution caution

CVE records for third-party Maltego integrations should not automatically be attributed to Maltego's core product. Public comparative material should distinguish core-product vulnerabilities from community or third-party integrations. [S13]

Vulnerability / security assessment

This vendor has the clearest confirmed core-product CVE in the reviewed set: CVE-2020-24656, affecting versions before 4.2.12.

Defensible wording: “Maltego before 4.2.12 was affected by CVE-2020-24656 (XXE, NVD CVSS 6.5); 2026 release notes also document remediation of critical/high dependency vulnerabilities.” [S13, S14]

Recorded Future

Primary risk signal: Third-party SaaS / OAuth supply-chain exposure in 2026

Klue incident

Recorded Future disclosed that a June 2026 security incident at third-party marketing vendor Klue affected the integration layer connecting Klue with Salesforce. Recorded Future said a compromised OAuth token enabled access to elements of its Salesforce account. [S15]

Scope stated by vendor

Recorded Future said the potentially impacted information was limited to business data fields such as client contact names, email addresses and potentially certain contract information. It reported no evidence that its proprietary systems, internal databases or customer platform data were accessed. [S15]

Vulnerability / security assessment

The significant documented issue in this research is a third-party integration compromise, not a confirmed compromise of Recorded Future's intelligence platform.

Defensible wording: “Recorded Future was affected by the June 2026 Klue/Salesforce OAuth supply-chain incident; the company said exposure was limited to business CRM data and did not affect its intelligence platform or customer platform data.” [S15]

Social Links

Primary risk signal: Client-account compromise + sensitive OSINT aggregation context

2025 CrimeWall account incident

Social Links disclosed that one SL CrimeWall client account was compromised. The company said its investigation attributed the origin to a breach on the customer's side and stated that Social Links infrastructure itself was not compromised. [S16]

Data aggregation scope

Social Links markets its Private Platform to government and enterprises, describing integration of its search capabilities with internal databases, third-party libraries and sensitive in-house data. [S18]

CVE attribution correction

CVE-2025-25112 is not a vulnerability in the Social Links intelligence vendor. NVD identifies the affected product as a separate WordPress project from vendor 'kareemsultan'. It should not be used in competitive claims against Social Links. [S17]

Vulnerability / security assessment

No verified Social Links intelligence-platform CVE was identified in this review. The 2025 client-account compromise should be described with the vendor's stated root cause.

Defensible wording: “Social Links disclosed a 2025 compromise of one CrimeWall client account, which it attributed to the client's environment; CVE-2025-25112 is unrelated and should not be attributed to Social Links.” [S16, S17, S18]

Fivecast

Primary risk signal: Broad collection / retention capabilities and police deployment

Collection and retention

Fivecast's ONYX product page describes continuous near-real-time targeted collection, secure obfuscation and retention of deleted data, with search across news, social media, search engines, corporate databases, sanctions lists, the dark web and data leaks. [S19]

NSW Police contract

A New South Wales government award notice states that NSW Police contracted Fivecast to monitor various social-media platforms for OSINT from July 2024 through June 2028. [S20]

UK policing framework

BlueLight Commercial lists Fivecast as a supplier on its 2026–2030 Open-Source Intelligence Screening Tools Framework for policing/public-sector screening. [S21]

Vulnerability / security assessment

No clearly attributable Fivecast/ONYX CVE or confirmed vendor infrastructure breach was identified in the reviewed public material.

Defensible wording: “Fivecast ONYX supports near-real-time targeted collection and deleted-content retention and is deployed in police/public-sector OSINT screening contexts in Australia and the UK.” [S19, S20, S21]

Use in Competitive Materials

For external advertising, sales decks or comparison charts, the safest approach is to use dated, source-linked factual statements and avoid implying that an allegation is proven, that a vulnerability is still unpatched, or that a vendor is currently compromised unless a current source establishes that fact.

RuleApplicationPrefer
Date the claimInclude the year for breaches, CVEs, court actions and vendor disclosures.“Documented Security, Privacy & Legal Concerns” or “Publicly Documented Risk Factors.”
Separate fact from allegationUse “alleged,” “class action authorized,” “lawsuit filed,” or “vendor states” where appropriate.
Avoid false CVE attributionEspecially for Social Links and third-party/community integrations around Maltego.
Preserve remediation contextIf a vulnerability is documented as fixed, say that it affected earlier versions rather than implying present exposure.
Use vendor responsesWhere a vendor disputes a claim or limits the reported scope, include that material context.

High-confidence factual claims from this research

  • 01Apollo: 2018 exposure involving 212M+ contact listings and approximately 9B data points. [S1]
  • 02Apollo: Québec privacy class action against ZenLeads/Apollo was authorized; authorization is not a liability finding. [S2]
  • 03Babel Street: Locate X was documented as enabling fine-grained commercial location-data analysis and has been used by U.S. government agencies. [S5, S6]
  • 04Maltego: CVE-2020-24656 affected versions before 4.2.12; NVD CVSS v3.1 6.5. [S13]
  • 05Recorded Future: June 2026 Klue/Salesforce OAuth incident affected business CRM data; vendor says proprietary systems/customer platform data were not compromised. [S15]
  • 06Social Links: one CrimeWall client account compromise was disclosed in 2025; vendor attributed root cause to the client's environment. [S16]
  • 07Fivecast: NSW Police contract and UK policing framework confirm public-sector OSINT screening deployments. [S20, S21]

Sources & Direct Links

Links below are clickable. Source descriptions are intentionally neutral; inclusion does not imply endorsement.

Research Disclaimer

This document is an OSINT research brief, not legal advice, a vulnerability assessment of vendor infrastructure, or a claim that any vendor is presently compromised. Findings reflect publicly available information reviewed through 15 September 2026. Court filings, class-action authorizations and advocacy-group assessments are presented with their procedural or attribution context. Before publishing a competitive claim, re-check the linked source for updates, corrections, settlements, patches or subsequent court decisions.

Vendor risk

Need this review for your own suppliers?

Tell us which vendors matter and we will scope an open-source review with you.

  • Open sources cited
  • Factual, not speculative
  • Scoped with you