Recorded Future A.I CyberSecurity Scoring
Recorded Future
Company Information
Website:http://www.recordedfuture.com
Employees number:1,152
Number of followers:87,544
NAICS:541514
Industry Type:Computer and Network Security
Homepage:recordedfuture.com
Recorded Future Risk Score (AI oriented)
Between 600 and 649
Recorded FutureComputer and Network Security
Updated:
15/07/2026
15/07/2026
643/1000
Poor
Caa
Recorded Future Global Score (TPRM)
xxxx
Recorded FutureComputer and Network Security
Score locked

Recorded FuturePoor
Current Score
643Caa (POOR)
01000
2 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
647
AUGUST 2026
647
JULY 2026
692
JUNE 2026
691
MAY 2026
690
APRIL 2026
688
MARCH 2026
687
FEBRUARY 2026
686
JANUARY 2026
684
DECEMBER 2025
681
NOVEMBER 2025
681
OCTOBER 2025
679
JUNE 2025
672
Breach
12 Jun 2025 • Recorded Future
LastPass, BeyondTrust, Klue, HackerOne, Jamf, Recorded Future, Snyk, Huntress and Tanium: Klue Data Breach 2026: 200 Firms Hit via Old Credential
Klue Breach Exposes 200 Firms via Forgotten 4-Year-Old Credential
609
CRITICAL-63
JAMHUNSNYRECHACLASTANKLUBEY1784126732
Klue Breach Exposes 200 Firms via Forgotten 4-Year-Old Credential
In June 2025, a dormant credential issued by competitive-intelligence platform Klue in 2022 became the entry point for a breach affecting nearly 200 companies, including prominent cybersecurity vendors. The attack, claimed by the extortion group Icarus, exploited an unmonitored OAuth token to access Salesforce environments, underscoring the risks of neglected third-party integrations.
### What Happened?
On June 12, 2025, attackers used a compromised legacy credential originally created for a "limited pilot" to infiltrate Klue’s systems. The credential, left active for four years, granted access to OAuth tokens that Klue used to pull data from connected Salesforce instances. Once inside, the threat actors automated data exfiltration from 195–200 companies, including LastPass, BeyondTrust, Jamf, HackerOne, Recorded Future, Snyk, Tanium, and Huntress.
Klue publicly disclosed the breach on June 15, 2025, confirming data theft from an unspecified number of customers. By late June, affected firms began acknowledging the incident, with LastPass and BeyondTrust clarifying that only business contact and CRM data not core product systems were exposed.
### How the Attack Unfolded
The breach required no zero-day exploits or sophisticated malware just an overlooked credential. The attackers leveraged Klue’s OAuth tokens to access Salesforce environments en masse, demonstrating the dangers of fourth-party risk: a vendor’s vendor (Klue) becoming the weak link in a supply chain.
### Key Victims & Impact
While Klue serves sales and marketing teams, its customer base included security vendors, amplifying the breach’s irony. Confirmed victims span:
- Password management (LastPass)
- Privileged access (BeyondTrust)
- Endpoint security (Tanium, Jamf)
- Threat intelligence (Recorded Future)
- Bug bounty coordination (HackerOne)
- Application security (Snyk)
Huntress reported receiving a ransom note from the attackers via a compromised Australian email address, highlighting the group’s reliance on reused infrastructure.
### Broader Context: A Year of Supply Chain Attacks
The Klue breach coincided with a separate 2026 supply chain campaign targeting open-source security tools, including Trivy, Bitwarden, and Checkmarx. While unrelated, both incidents reflect a trend: attackers increasingly compromise trusted platforms to bypass direct defenses.
### Regulatory & Industry Reactions
- Cyber insurers are tightening scrutiny of third-party integrations, particularly OAuth token hygiene.
- Security vendors on the victim list face heightened procurement questions from enterprise buyers.
- Regulators are paying closer attention to software supply chain risks, though the Klue breach limited to business data may not trigger major notifications.
### Lessons from the Breach
The incident mirrors the 2025 Salesloft Drift breach, where stolen OAuth tokens compromised 700+ Salesforce environments. Both cases reveal a critical gap: point-in-time vendor assessments fail to catch dormant credentials. Mitigation requires:
- Automated expiration for pilot credentials.
- Minimum-scoped OAuth grants (avoiding broad CRM access).
- Recurring token audits to identify stale integrations.
As of June 2026, only ~15 of the estimated 200 affected firms have publicly confirmed exposure, with more expected to disclose as investigations continue. The breach serves as a stark reminder that identity and credential management not just perimeter defenses are central to modern cybersecurity.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2024
759
Ransomware
01 Aug 2024 • Recorded Future
ALPHV/BlackCat and Pay2Key: Iranian hackers target US critical infrastructure through ransomware proxies, KELA warns
Iranian State-Backed Threat Actors Blur Lines Between Cybercrime and Espionage
652
CRITICAL-107
RECKEL1774988711
Iranian State-Backed Threat Actors Blur Lines Between Cybercrime and Espionage
Recent intelligence from KELA reveals a troubling evolution in Iranian state-sponsored cyber operations, where nation-state actors increasingly collaborate with criminal ransomware groups to conduct financially motivated attacks under the guise of extortion. Rather than operating standalone ransomware cartels, these groups now embed themselves within the cybercriminal ecosystem acting as initial access brokers, partnering with ransomware affiliates, and deploying pseudo-ransomware to mask destructive campaigns as profit-driven attacks.
A prime example is Pay2Key, an Iran-linked ransomware operation that has resurfaced as a professionalized Ransomware-as-a-Service (RaaS) platform on the anonymous I2P network. The group now actively recruits affiliates from Russian cybercrime forums, offering an 80% profit share up from the typical 70% for attacks targeting U.S. and Israeli organizations. This model poses significant compliance risks: victims paying ransoms may unknowingly fund OFAC-sanctioned Iranian entities, exposing themselves to severe legal and financial penalties.
A joint advisory from the FBI, CISA, and DoD Cyber Crime Center in August 2024 highlighted groups like Pioneer Kitten (UNC757/Fox Kitten), which specialize in exploiting vulnerabilities in VPNs and firewalls to gain initial access. Instead of deploying their own ransomware, these actors hand off compromised networks to affiliates such as NoEscape, RansomHouse, and ALPHV/BlackCat, taking a cut of ransom payments. This collaboration enables Iranian hackers to generate revenue while providing ransomware groups with streamlined access to high-value targets, including healthcare, education, and financial institutions in the U.S.
Pay2Key’s evolution underscores Iran’s use of ransomware as a geopolitical tool. Initially launched in 2020 by the Fox Kitten group to target Israeli organizations, the operation combined extortion with information warfare, leveraging data leaks to pressure adversaries. By 2025, it had rebranded as Pay2Key.I2P, adopting a more aggressive, scalable RaaS model that blends political objectives with criminal enterprise.
Beyond financial motives, Iranian actors have repeatedly used ransomware-style encryption as a cover for destruction. The Agrius APT group, for instance, repurposed the Apostle malware originally a data wiper into a ransomware variant, disguising sabotage as extortion. A similar tactic was observed in July 2022, when an Iranian state-sponsored actor deployed ROADSWEEP ransomware alongside a destructive wiper against Albanian government networks, framing the attack as a ransom operation despite its true intent being disruption.
Attribution challenges are further complicated by "moonlighting" where Iranian operatives use state-provided tools and access for personal financial gain. In April 2024, the U.S. DOJ and Treasury Department sanctioned individuals linked to Mahak Rayan Afraz, a front company for the IRGC’s Cyber-Electronic Command, after operatives were found running ransomware schemes alongside official state duties.
The convergence of state-sponsored cyber warfare and cybercrime creates serious legal and operational risks for organizations. Paying ransoms to seemingly independent groups may violate OFAC sanctions if those groups have undisclosed ties to Iran, leading to heavy penalties. The shift demands heightened vigilance, as traditional security measures such as patching and backups must now account for hybrid threats that blend espionage, sabotage, and financial crime.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Recorded Future ??
What was Recorded Future's A.I Rankiteo Cyber Score in August 2026 ??
What was Recorded Future's A.I Rankiteo Cyber Score in July 2026 ??
What was Recorded Future's A.I Rankiteo Cyber Score in June 2026 ??
What was Recorded Future's A.I Rankiteo Cyber Score in May 2026 ??
What was Recorded Future's A.I Rankiteo Cyber Score in April 2026 ??
What was Recorded Future's A.I Rankiteo Cyber Score in March 2026 ??
What was Recorded Future's A.I Rankiteo Cyber Score in February 2026 ??
What was Recorded Future's A.I Rankiteo Cyber Score in January 2026 ??
What was Recorded Future's A.I Rankiteo Cyber Score in December 2025 ??
What was Recorded Future's A.I Rankiteo Cyber Score in November 2025 ??
What was Recorded Future's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on Recorded Future's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Recorded Future ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Recorded Future's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?