Publicly Documented Security, Privacy & Legal Risk Findings
OSINT & Intelligence Vendors — Comparative Research Brief
Scope: Skopenow • Recorded Future • Social Links • Babel Street • Fivecast • Maltego • ShadowDragon • Apollo.io RECON is intentionally excluded from the adverse-vendor research scope.
L&F Research Desk
Research date: 15 September 2026 • 8 min read
Basis: publicly available sources, vendor disclosures, vulnerability databases, court records and civil-liberties research
Research framing. The user's phrase “dirty secrets” is operationalized here as documented adverse information: security incidents, product vulnerabilities, privacy and surveillance controversies, litigation, and other material public-risk signals. Allegations are identified as allegations; an authorized class action or filed lawsuit is not a finding of liability.

Executive Summary
The strongest publicly documented adverse findings in this vendor set fall into four distinct categories: large-scale data exposure (Apollo), product vulnerability / dependency remediation (Maltego), third-party SaaS compromise (Recorded Future), and privacy / surveillance controversy (especially Babel Street, with Skopenow, ShadowDragon and Fivecast also appearing in public-sector monitoring contexts). [S1, S7, S13, S14, S15]
- Apollo.io: 2018 exposure of 212M+ contact listings and ~9B data points; 2026 Québec privacy class action authorized; ongoing patent litigation with ZoomInfo. [S1, S2, S3]
- Babel Street: Locate X has been documented as enabling highly granular location analysis; government use and civil-liberties concerns are well documented. [S5, S6, S7]
- Maltego: CVE-2020-24656: XXE in versions before 4.2.12, NVD CVSS 6.5; 2026 release notes document remediation of critical/high-severity dependency vulnerabilities. [S13, S14]
- Recorded Future: June 2026 Klue/Salesforce OAuth supply-chain incident exposed business CRM information; vendor states core intelligence systems and customer platform data were not compromised. [S15]
- Others: Social Links disclosed one client-account compromise attributed to the client's environment; Skopenow, ShadowDragon and Fivecast show stronger public-risk signals around monitoring scope, government use and privacy than around published CVEs. [S8, S9, S11, S16, S19, S20, S21]
Methodology & Limitations
This report uses public sources available as of 15 September 2026, prioritizing primary vendor disclosures, NIST NVD, court/docket materials, government procurement records, and established journalism or civil-liberties research. The absence of a located CVE or breach should not be interpreted as proof that none exists. Search results are not exhaustive, and vendor security posture changes over time.
Monitoring policy: CTI and AML sources are rechecked every 15 days. Source changes, new reporting and unverified allegations are recorded for human editorial review; they are not automatically published as facts. Inaccessible sources remain explicitly unverified. Checks resume when the API service is running.
Comparative Findings Matrix
| Vendor | Security incident | Privacy / legal / surveillance | Vulnerability signal | Sources |
|---|---|---|---|---|
| Apollo.io | Confirmed major data exposure (2018) | Privacy class action authorized; patent litigation | No comparable current core-product CVE located | [S1, S2, S3, S4] |
| Babel Street | No vendor breach located in reviewed sources | High-profile location-data / surveillance controversy | No vendor-specific public CVE located | [S5, S6, S7] |
| Skopenow | No vendor breach located in reviewed sources | Law-enforcement monitoring use; Daniel's Law-related litigation | No attributable public CVE located | [S8, S9, S10] |
| ShadowDragon | No vendor breach located in reviewed sources | ICE / DHS monitoring use and civil-liberties scrutiny | No clearly attributable public CVE located | [S11, S12] |
| Maltego | No major breach located in reviewed sources | Limited controversy relative to peers in this review | CVE-2020-24656; critical/high dependency fixes documented in 2026 | [S13, S14] |
| Recorded Future | Third-party Klue/Salesforce incident (2026) | No comparable major privacy controversy located | No core-product CVE highlighted in this research | [S15] |
| Social Links | Single CrimeWall client account compromise disclosed (2025) | Government/enterprise OSINT and sensitive data aggregation context | CVE-2025-25112 is unrelated and must not be attributed to this vendor | [S16, S17, S18] |
| Fivecast | No vendor breach located in reviewed sources | Near-real-time collection, deleted-content retention, police/public-sector deployment | No clearly attributable public CVE located | [S19, S20, S21] |
Note: “No CVE located” means none was identified in the reviewed public material; it is not a warranty of absence.
Detailed Vendor Risk Findings
Apollo.io / ZenLeads
2018 data exposure
WIRED reported that a publicly accessible Apollo data trove contained more than 212 million contact listings and about 9 billion data points. The exposed material included publicly sourced professional data and private customer-imported information, including Salesforce-derived sales data. [S1]
2026 Québec privacy class action
In Badji c. Zenleads inc., the Superior Court of Québec authorized a class action over alleged collection, use, communication and commercialization of personal information without consent. The court’s authorization allows the claims to proceed; it is not a final finding of liability. Osler's 2026 review also notes leave to appeal. [S2]
Current data-broker model
Apollo's current privacy policy states that it operates as a registered B2B data broker and may make professional contact information such as names, email addresses, phone numbers, employment history and social-network URLs available to customers. Its U.S. state disclosure also describes categories that may be sold or shared, subject to applicable law. [S4, S22]
Patent litigation
ZoomInfo Technologies sued ZenLeads d/b/a Apollo.io in the U.S. District Court for the District of Delaware in 2025 alleging patent infringement. The docket remained active in 2026. Litigation allegations should not be presented as established misconduct. [S3]
Vulnerability / security assessment
No current Apollo core-product CVE comparable to Maltego's CVE-2020-24656 was identified in the reviewed sources. The most significant documented security event is the 2018 data exposure.
Babel Street
Locate X granularity
A 2024 NOTUS investigation reported that researchers using Babel Street's Locate X could follow device movement to sensitive locations and, when paired with people-search information, potentially identify supposedly anonymous devices. The reporting highlighted weak controls in the broader commercial location-data ecosystem. [S5]
Government use
VICE reported from a Secret Service contract that the agency purchased access to Babel Street's Locate X, a product based on location data generated by ordinary apps. The report framed the acquisition as part of the debate over government purchase of data that might otherwise require legal process. [S6]
Human-rights concerns
Amnesty International reported in 2025 that Babel X capabilities could support persistent, automated monitoring of migrants and others, based on reviewed public records and procurement/privacy documents. This is an advocacy organization's assessment, not a court finding. [S7]
Vulnerability / security assessment
No reliable vendor-specific Babel Street CVE was identified in the reviewed material. The dominant adverse-risk signal is privacy, surveillance scope and potential misuse rather than a published software exploit.
Skopenow
Monitoring capabilities
The Brennan Center summarized Skopenow as offering anonymous social-media data collection, behavioral recognition analysis, subject monitoring, automated alerts and visualizations combining location, consumer-report and social-media information. The report also documented law-enforcement demos/trials and government clients. [S8]
Daniel's Law-related litigation
Skopenow has been involved in litigation connected to New Jersey's Daniel's Law. In a 2026 filing, Skopenow stated that it does not maintain its own database, that its platform is not public, and that it serves vetted institutional clients; it disputed the plaintiffs' characterization and asserted good-faith compliance efforts. The existence of litigation is not proof of liability. [S9, S10]
Vulnerability / security assessment
No attributable public Skopenow CVE was identified in the reviewed sources.
ShadowDragon
ICE / DHS procurement
The Brennan Center obtained contracts showing ICE purchased ShadowDragon SocialNet licenses and OI Monitor. The Center reported that the tools were intended to help analysts map online networks, aliases, associates and possible lifestyle/location inferences. [S11]
Vendor position
ShadowDragon's Trust Center says its products access only publicly available and lawfully accessible information and acknowledges public concerns about misuse and the broader implications of investigative technology. [S12]
Vulnerability / security assessment
No clearly attributable public ShadowDragon CVE was identified in the reviewed sources.
Maltego
CVE-2020-24656
NIST's National Vulnerability Database states that Maltego before version 4.2.12 allowed XML External Entity (XXE) attacks. NVD assigns CVSS v3.1 6.5 (Medium), with high confidentiality impact and user interaction required. [S13]
2026 dependency remediation
Maltego's 2026 Graph Desktop release notes document updates to Keycloak, Jackson, Guava and Bouncy Castle dependencies to remove critical and/or high-severity vulnerabilities. The release notes demonstrate active remediation; they do not by themselves show that every dependency issue was exploitable in Maltego's deployed context. [S14]
Attribution caution
CVE records for third-party Maltego integrations should not automatically be attributed to Maltego's core product. Public comparative material should distinguish core-product vulnerabilities from community or third-party integrations. [S13]
Vulnerability / security assessment
This vendor has the clearest confirmed core-product CVE in the reviewed set: CVE-2020-24656, affecting versions before 4.2.12.
Recorded Future
Klue incident
Recorded Future disclosed that a June 2026 security incident at third-party marketing vendor Klue affected the integration layer connecting Klue with Salesforce. Recorded Future said a compromised OAuth token enabled access to elements of its Salesforce account. [S15]
Scope stated by vendor
Recorded Future said the potentially impacted information was limited to business data fields such as client contact names, email addresses and potentially certain contract information. It reported no evidence that its proprietary systems, internal databases or customer platform data were accessed. [S15]
Vulnerability / security assessment
The significant documented issue in this research is a third-party integration compromise, not a confirmed compromise of Recorded Future's intelligence platform.
Defensible wording: “Recorded Future was affected by the June 2026 Klue/Salesforce OAuth supply-chain incident; the company said exposure was limited to business CRM data and did not affect its intelligence platform or customer platform data.” [S15]
Social Links
2025 CrimeWall account incident
Social Links disclosed that one SL CrimeWall client account was compromised. The company said its investigation attributed the origin to a breach on the customer's side and stated that Social Links infrastructure itself was not compromised. [S16]
Data aggregation scope
Social Links markets its Private Platform to government and enterprises, describing integration of its search capabilities with internal databases, third-party libraries and sensitive in-house data. [S18]
CVE attribution correction
CVE-2025-25112 is not a vulnerability in the Social Links intelligence vendor. NVD identifies the affected product as a separate WordPress project from vendor 'kareemsultan'. It should not be used in competitive claims against Social Links. [S17]
Vulnerability / security assessment
No verified Social Links intelligence-platform CVE was identified in this review. The 2025 client-account compromise should be described with the vendor's stated root cause.
Fivecast
Collection and retention
Fivecast's ONYX product page describes continuous near-real-time targeted collection, secure obfuscation and retention of deleted data, with search across news, social media, search engines, corporate databases, sanctions lists, the dark web and data leaks. [S19]
NSW Police contract
A New South Wales government award notice states that NSW Police contracted Fivecast to monitor various social-media platforms for OSINT from July 2024 through June 2028. [S20]
UK policing framework
BlueLight Commercial lists Fivecast as a supplier on its 2026–2030 Open-Source Intelligence Screening Tools Framework for policing/public-sector screening. [S21]
Vulnerability / security assessment
No clearly attributable Fivecast/ONYX CVE or confirmed vendor infrastructure breach was identified in the reviewed public material.
Use in Competitive Materials
For external advertising, sales decks or comparison charts, the safest approach is to use dated, source-linked factual statements and avoid implying that an allegation is proven, that a vulnerability is still unpatched, or that a vendor is currently compromised unless a current source establishes that fact.
| Rule | Application | Prefer |
|---|---|---|
| Date the claim | Include the year for breaches, CVEs, court actions and vendor disclosures. | “Documented Security, Privacy & Legal Concerns” or “Publicly Documented Risk Factors.” |
| Separate fact from allegation | Use “alleged,” “class action authorized,” “lawsuit filed,” or “vendor states” where appropriate. | |
| Avoid false CVE attribution | Especially for Social Links and third-party/community integrations around Maltego. | |
| Preserve remediation context | If a vulnerability is documented as fixed, say that it affected earlier versions rather than implying present exposure. | |
| Use vendor responses | Where a vendor disputes a claim or limits the reported scope, include that material context. |
High-confidence factual claims from this research
- 01Apollo: 2018 exposure involving 212M+ contact listings and approximately 9B data points. [S1]
- 02Apollo: Québec privacy class action against ZenLeads/Apollo was authorized; authorization is not a liability finding. [S2]
- 03Babel Street: Locate X was documented as enabling fine-grained commercial location-data analysis and has been used by U.S. government agencies. [S5, S6]
- 04Maltego: CVE-2020-24656 affected versions before 4.2.12; NVD CVSS v3.1 6.5. [S13]
- 05Recorded Future: June 2026 Klue/Salesforce OAuth incident affected business CRM data; vendor says proprietary systems/customer platform data were not compromised. [S15]
- 06Social Links: one CrimeWall client account compromise was disclosed in 2025; vendor attributed root cause to the client's environment. [S16]
- 07Fivecast: NSW Police contract and UK policing framework confirm public-sector OSINT screening deployments. [S20, S21]
Sources & Direct Links
Links below are clickable. Source descriptions are intentionally neutral; inclusion does not imply endorsement.
Research Disclaimer
This document is an OSINT research brief, not legal advice, a vulnerability assessment of vendor infrastructure, or a claim that any vendor is presently compromised. Findings reflect publicly available information reviewed through 15 September 2026. Court filings, class-action authorizations and advocacy-group assessments are presented with their procedural or attribution context. Before publishing a competitive claim, re-check the linked source for updates, corrections, settlements, patches or subsequent court decisions.
Vendor risk
Need this review for your own suppliers?
Tell us which vendors matter and we will scope an open-source review with you.
- Open sources cited
- Factual, not speculative
- Scoped with you
