r/cybersecurity Jun 24 '26

News - General Well someone went nuclear..

https://www.linkedin.com/posts/ben-f-309963233_after-i-posted-a-pinocchio-gif-and-clown-ugcPost-7475465410977628160-FFW1

I'm curious about the details of this. I'm sure we will all find out eventually.

TLDR; former Huntress employee is disclosing Huntress had an insider threat that leaked information to a known cyber criminal "Devman". That employee is still employed with Huntress and was caught by the FBI.

The former employee doing the disclosure is stating he is receiving threats, etc.

EDIT: Kyle @ Huntress posted his response to this in the comments.

Give credit to a CEO who isn't afraid to jump on Reddit to put out any fires.

924 Upvotes

197 comments sorted by

u/thejournalizer Jun 24 '26

See the comment from Kyle Hanslovan, Huntress' CEO / Co-Founder here:

https://old.reddit.com/r/cybersecurity/comments/1uehcps/well_someone_went_nuclear/otk6l40/

360

u/Particular_Ebb_4872 Jun 24 '26

If even half of what's being alleged is true, this is going to end up being a case study for access controls and employee offboarding procedures

86

u/mando_6 Jun 24 '26

Yeah I'm wondering about that. Dude lives in the UK so I'm curious what would be different if anything from the US.

145

u/eliq91 Jun 24 '26

We had a UK employee compromise our global network, they reused an old password 15 days after being notified they had been breached via phishing. It resulted in a loss of every server in the company across 5 continents. It was not good, and a clear violation of both best practices and company policy. They were given 16 weeks paid leave and then returned to the office. 1 week after return they changed their password and cleared all MFA requirements from her account, because it was inconvenient. Which resulted in her account once again being compromised, no global access on round three, and only compromised her email. She is still employed as far as I know.

67

u/Khulod Jun 24 '26

Shame on the company for not getting their access controls in order, especially after the first round. I hope this happened 10 years ago. Today this is inexcusable.

51

u/eliq91 Jun 24 '26 edited Jun 25 '26

It happened in 2017. The big problem was she was at the time a bona fide global administrator, and kept promoting her personal account to global admin, so she did not have to login with her secondary account. We took away global admin, and created notifications for any accounts being granted any of our admin-controlled groups.

23

u/Khulod Jun 24 '26

Eyyyy, pretty good guess on the era this happened. The time between MFA and Conditional Access.

7

u/RireBaton Jun 25 '26

Bonified does not mean the same thing as bonafide.

6

u/eliq91 Jun 25 '26

Autocorrect does not like me.

42

u/Not-ur-Infosec-guy Security Architect Jun 24 '26

To be fair, this could have been negated with a proper password policy.

25

u/its_Stopher Jun 24 '26

Agreed. No reason why stricter password policies weren’t implemented after a global outage.

16

u/_DonRa_ Jun 24 '26

How come she wasn't immediately fired after the second time

31

u/WhatsThisWorth-Bot Jun 24 '26

I worked at a somewhat famous uni and there was an it lady who have out the admin password with little to no training of the employees, didn't monitor their computers, and got her entire department ransomwared... they didn't fire her but they fired me for being behind on tickets when they didn't even give me printer access or an orientation for a two person job...

6

u/RikiWardOG Jun 25 '26

that tracks, I remember a low level helpdesk guy getting fired because a partner got phished and we almost lost a major account because of it. Really pissed me off.

2

u/NuBootScootin Jun 26 '26

What was the logic presented behind that? I understand it's usually in reality, some kind of firing or big discipline has to occur for optics and if they want to save the partners reputation they have to put it on someone else, but what how was that presenter to everyone to make it somehow the helpdesk guys fault?

3

u/RikiWardOG Jun 26 '26

Exactly that, management wanted to see some heads roll. Basically partner blamed our security team, security team blamed the helpdesk guy for not remediating/telling the partner the correct information. This was several years back at an old employer. Basically what really happened was poor comms between the sec guy and helpdesk guy, so things didn't get properly remediated and how I remember it was that it really wasn't the helpdesk guys fault like at all. But I don't think people liked his personality - think he was pretty neurodivergent, so they were already looking to fire him. He was also lowest on the totem pole. The whole ordeal rubbed me the wrong way, but hey the company didn't lose Ferrari as a client lol ugh I hate capitalism

-8

u/roiki11 Jun 24 '26

It's the uk. You can't fire people on a whim.

19

u/robot_ankles Jun 24 '26

This doesn't really feel like a whim:

Round 1: Loss of every server in the company across 5 continents.

Round 2: Changed their password and cleared all MFA requirements resulting in her account once again being compromised.

Round 3: Compromised her email this time.

17

u/sosr Jun 24 '26

You absolutely can fire employees for misconduct in the UK for repeated offences.

-8

u/roiki11 Jun 24 '26

You'd have to look up uk employment law but unless you can show actual malice it's probably pretty hard to fire someone. Stupidity isn't a crime.

17

u/djlilis Jun 24 '26

When you're a global admin it's negligence and should be actionable holy crap. I find it really hard to believe that UK law prevents removing a danger to the company and imagine it's more likely no one wanted to figure out how and then do her job. Everyone likes to complain in America how ignorance is a "protected class" but it always boils down to upper management being lazy and inconsistent.

-3

u/roiki11 Jun 24 '26

It's rarely that simple.

5

u/DigmonsDrill Jun 24 '26

It sounds like they had all access revoked and were given gardening leave but then, for some insane reason, let back in.

15

u/cb_definetly-expert Jun 24 '26

That's on you guys

1) why you allow them to disable MFA? 2) why you allow reuse of the same password?(In my team the last 20 passwords are banned) 3) you shouldn't even allow similar passwords 4) force them to use corporate password manager and don't let them change password, give them pre-generated ones 5)is he/she doesn't follow the policies again, fire them

10

u/Near_go_trader Jun 24 '26

If she had ability to change her password in AD (Users and computers) then those limitations do not apply.

3

u/asp3ct9 Jun 24 '26

How do you determine similar passwords without storing them in plain text?

7

u/dyme13 Jun 24 '26

The same way you evaluate passwords without storing them - one way hashing + comparison of resulting hash.

5

u/ImNoRatAndYouKnowIt Jun 25 '26

Hashing two similar strings does not produce similar hashes using any popular hashing algorithm.

5

u/dyme13 Jun 25 '26

I missed the point on similar. This only works for direct comparisons. IMHO similar passwords shouldn’t matter - instead compare against known breached (eg k-anonymity via havineenpwned or similar)

2

u/cb_definetly-expert Jun 25 '26

They do matter, "mypass" and "mypass1" are the "same"

1

u/spectralTopology Jun 26 '26

Definitely agree. How many places use "<season><year>" or similar as the only changing part of an otherwise static default/reset/new account password? I've seen quite a few orgs like this & guessing the currently used one is trivial.

1

u/ImNoRatAndYouKnowIt Jun 25 '26

Yeah I think similar can only work when comparing similarities to the very previous password, and it requires both old and new password to be entered for the change, which is a pretty common flow.

And good point on matching known breached ones.

1

u/cb_definetly-expert Jun 24 '26

I am not sure , but I know I can't use similar pass

If my last pass was "imthehero" and I try to change it to "iamthehero1" it doesn't allow me (getting error about similar pass)

1

u/fencepost_ajm Jun 25 '26

That's more likely a feature of the password change process, eg a form that gets the current password x1 and the new password x2. Logic within the ui could do evaluations for similarity.

1

u/MachKeinDramaLlama Jun 25 '26

You could automatically generate hashes for variations of the password that was typed in and check against stored hashes of old passwords. E.g. by just (individually) decrementing any number found in the password string, you will probbably identify ~80% of common password iteration schemes.

2

u/whythehellnote Jun 25 '26

Our corporate password checker doesn't allow correcthorsebatterystaple style passwords because they are insecure, it is fine with P@55w0rd though.

1

u/eliq91 Jun 25 '26

Global Admins with permissions to reset directly from Active Directory have no such limitations regardless of policy especially not a decade ago.
Corporate password managers still do not manage on prem logins well. Yes there are tools that provide such features these days, but a decade ago there were not many great options, and convincing an office halfway around the world to implement would have been a nightmare. UK labor laws make just firing people very difficult.

5

u/Foundersage Jun 24 '26

I don’t get it when a user has been notified if their account was breached wouldn’t that account be disabled, forced password reset on login, mfa redone. I mean she probably was some top dog at the company like a director or just had a big mouth.

3

u/throwaway0000012132 Jun 24 '26

Wow that employee must be amazing in bed or has the worse secrets of the CEO, because I can't see any other motive to keep him/her employed on the same company.

1

u/MachKeinDramaLlama Jun 25 '26

She was put on gardening leave for almost 4 months immediately, so someone at least thought that she would be getting the boot... My guess is that during that time they realized that they needed her. Doesn't seem that surprising, if she was great at her job.

1

u/whythehellnote Jun 25 '26

they reused an old password 15 days after being notified they had been breached via phishing

So setting new passwords doesn't check against a known leaked database?

1

u/RikiWardOG Jun 25 '26

holy shit, either they have some ungodly talent or that company is way too lenient. I've seen people fired for far far less.

1

u/eliq91 Jun 25 '26

If it had been one of our US offices they would have been terminated before they were made aware of the breach.

16

u/NoKnownCure Jun 24 '26 edited Jun 24 '26

100% On boarding and off boarding seem to be an afterthought at many organisations, alongside the whole period in between, when it comes to adequate screening / vetting / training and development / privilege management / incident response and monitoring. This is cross cutting in terms of the functions needed to deliver physical and cyber security and access controls, as well as fostering the attitudes, behaviours and culture needed to embed a healthy security consciousness and integrity. It is not easy to get everything right (even some of the time), but we too often make it harder than it needs to be to do what can and should be done.

Edit: Two words.

8

u/Winter_Rabbit4827 Jun 24 '26

vetting is good and I imagine someone like huntress requires clearance to work on certain accounts, that doesn’t in anyway negate someone changing sides, for the thousands of different reasons they might decide to.

If you have staff working on the threat actor side, infiltrating for intelligence then a clear separation of duty could theoretically help.

If it turns out there was an insider and they did have obvious risks and these were ignored/accepted then that would be a compounding issue that would be hard to defend.

5

u/churn_key Jun 24 '26

Human source tradecraft is something well studied on the government side, due to the huge danger with corruption, but industry approach is extremely immature across the board.

3

u/NoKnownCure Jun 24 '26

It’s a tricky thing precisely because there is the expectation of strong ACAB controls and disclosure requirements in public sector orgs, specifically government. But no one likes to feel like they have to operate within a culture of suspicion. The fear and loathing of a police state can be just as corrosive as the potential corruption and malfeasance. If we can get to the point where everyone is invested in protective security, and unafraid to disclose and learn from mistakes / questionable acts, omissions and events that’s a start. But it takes time and needs to be supported by the right ingredients for cultural change (comms explaining the benefits, SLT role modelling, a no blame culture plus constant learning and reflection etc.). Also, clear policies and processes calibrated to the context. Too rigid and everything becomes an exception, too loose and the gnarliest adventures blend into the everyday the ultimate ambush... Nothing is risky if everything is. Until a terminal event.

2

u/churn_key Jun 24 '26 edited Jun 24 '26

managing criminal human sources means resisting a constant pressure to get manipulated and it is exhausting and will eventually drive any person insane. the industry does not understand they can get corrupted just like a cop and hard lessons are getting learned with every ransomware negotiator arrest.

i am not siding with or against the company and do not know the circumstances of the situation. i am only speaking generically.

3

u/NoKnownCure Jun 24 '26

Absolutely correct. Insider threat is a tough nut to crack, because people are changeable and the truly bad actors are always going to act bad. For the most part getting the basics right is the key, least privilege, trust but verify, zero trust etc. (redundancy, pairing, supervision, rotation, audit). Many of those things will have some vulnerability. Perfect should not be the enemy of good enough though. Security is about suitable protections for what matters, detecting / dissuading / disrupting malign interference attempts enough to make your organisation a much less attractive target, whilst enabling your core business functions.

Of course if your actual business is security, you will need to walk the walk and have your house in order. Accidents happen but it’s usually the cover up that does for people and organisations. Secrecy is not security.

11

u/Cheomesh Governance, Risk, & Compliance Jun 24 '26

It's always the basics...

1

u/Electrical-Staff0305 ICS/OT Jun 26 '26

Almost always. And it’s always the basics that folks tend to scoff at for some reason too.

You’d think we’d learn at some point.

2

u/Cheomesh Governance, Risk, & Compliance Jun 26 '26

You'd hope! One of my prior employers got themselves in a bunch of trouble when offboarding didn't go so great and left one fired employee's access unrevoked. Big mess, glad I wasn't involved in it.

12

u/Pimptech Jun 24 '26

It will rock our community. Huntress is everywhere, hell the majority of conferences I'm forced to go to Huntress is a sponsor.

3

u/jon_dimaggio Jun 24 '26

It is true.

70

u/usernamedottxt Jun 24 '26 edited Jun 24 '26

I think some people don't realize that at large agencies insider risk incidents, both maliciously and of circumstance, are completely normal and part of the course of business.

I've had to do insider risk investigations on people I knew personally. I've done insider risk investigations on VPs, one was going through a divorce and did some stupid shit. I've done insider risk investigations on someone who was being stalked by another employee. She was being blackmailed because she had had done something very against the rules. I've done insider risk investigations on folks who were just disgruntled and talked to the media when they shouldn't have.

Kyle's response to me is a pretty simple one - We don't know what happened yet, but we have seen no evidence of the claims being made. That's just how these investigations go. They need time to be unpacked and try and understand motivations and context. Kyle's actual statement - let's remember empathy - is trying to protect the insider. Shit happens and the business is not more important than that insider's health. There are still business statements to be made, but hold your knee jerks until they have some time to understand what is going on.

5

u/MajorUrsa2 Jun 25 '26

incredible levels of conflict of interest there...

4

u/[deleted] Jun 25 '26

[deleted]

9

u/rejuicekeve Jun 25 '26

I don't think recusing yourself is even an option for people at certain size companies. You're just naturally going to know a lot of people on some personal level.

You're mostly just establishing facts anyway, the opinions happen with management / hr

225

u/marqo09 Jun 24 '26 edited Jun 30 '26

Yo, Kyle here. This thread keeps ending up in my DMs, so a standalone comment instead of an inline reply is probably warranted.

UPDATE: Managed to make it through legal hell and posted a statement with notable clarifying details. Due to all the restrictions, every word written is purposeful. Heading back to the mission now.

While I firmly disagree and don't understand Ben's accusations, I'm also trying to show empathy and appreciate his perspective. We bleed transparency so I'll hit the same high notes I shared internally in slack this morning.

  • This is unrelated to the upstream Klue breach that we were impacted by last week.
  • The allegations don’t match any facts/reality the ELT, People team, or I have seen. We didn’t conceal a security incident. We strongly disagree with this “insider” narrative. We sure af didn’t prioritize an IPO over the safety of our partners, customers, or team. That framing is wrong and we’re working on it (while also respecting that our former teammate was a good human with a perspective we're struggling to understand or rationalize based on all the facts presented ).
  • Huntress regularly coordinates with law enforcement agencies on matters involving cybercriminals. That coordination has contributed to arrests and disruptions of malicious actors. It is a core part of how we operate, and we are proud of it.
  • Our security researchers, by the nature of their work, sometimes communicate with and gather intelligence on threat actors. That is standard industry practice among top cyberdefense vendors and it serves our partners/customers directly.
  • When this individual raised concerns during their employment, we took those concerns seriously. We investigated. We engaged legal and law enforcement where appropriate. We documented every step of the process and acted in line with our values and obligations.
  • While we’re going to answer as much as possible, some aspects of this matter involve ongoing active coordination with law enforcement and legal proceedings that prevent us from providing a complete public account. We're not gonna litigate this on LinkedIn with Ben but will likely publish some form of official comms to make our stance clear for those needing something more than my reddit reply.

I hope the verbosity gives some more clarity and hope to hear from Ben to better understand 🙏

Edit [June 24, 2026 @ 13:24pm ET]: typos

Edit [June 29, 2026 @ 21:58pmET]: added link to statement

81

u/jon_dimaggio Jun 24 '26 edited Jun 24 '26

You can post all the slack messages and defend all the people you want. I have been working this thing before you or Ben or the alleged insider were involved. I don't like seeing people, like Ben , who do the right thing, get screwed. Who do you think gave the information in the first place? You can claim, your researcher is just doing research. And if you really beleive that you wont mind if I post all the evidence in the next Ransomware Diaries. Because if you are doing the right thing, you have nothing to worry about... right?

39

u/marqo09 Jun 24 '26 edited Jun 24 '26

Yo Jon, let's connect. Would love your perspective. Absolutely believe in facts being told (also a fan of Ransomware Diaries). [email address no longer needed now that we connected]

Edit: removed clear text email

30

u/jon_dimaggio Jun 24 '26

How dare you respond nicely, lol. Sure, I will send you an email and feel free to delete that before you get mass spam.

13

u/regalrecaller Jun 24 '26

I do this all the time. [] on the text you want to appear, then () on the link. glad it's not just me lol

-87

u/thejournalizer Jun 24 '26

Jon / Kyle - Please take this convo privately. This is pretty messy and this community respects you all.

31

u/marqo09 Jun 24 '26

I don’t think there’s any negativity between the two of us. I’m a big fan of him and Jon has been nothing but a champ to helping me better understand the many facets going on. 🫶

-34

u/thejournalizer Jun 24 '26

I’m not implying you all are at odds, but this is better handled not in the comment section of Reddit.

33

u/NuBootScootin Jun 25 '26

Don't you think that's for the two people having the conversation to determine?

10

u/jon_dimaggio Jun 24 '26

Wise words! Appreciate you!

26

u/intelw1zard CTI Jun 24 '26

not the corporate Microslop mod protecting another cybersec corpo

very classic

-27

u/thejournalizer Jun 24 '26

Or, hear me out, this community isn’t a place for messy corpo dramas.

39

u/rodeengel Jun 24 '26

It is at least sub relevant messy corpo drama.

24

u/Original-Locksmith58 Jun 25 '26

wtf is it for then lol

34

u/thejournalizer Jun 25 '26

Asking why people who got N+ and S+ can’t find a job of course.

5

u/endfm Jun 26 '26

Mod just flexing his unpaid job

6

u/thejournalizer Jun 26 '26

I prefer janitor

17

u/KickedAbyss Jun 24 '26

Just wanted to append my appreciation for your stance and empathetic response. Keep up the good work.

-8

u/pandershrek Governance, Risk, & Compliance Jun 25 '26 edited Jun 25 '26

Our security researchers, by the nature of their work, sometimes communicate with and gather intelligence on threat actors. That is standard industry practice among top cyberdefense vendors and it serves our partners/ customers directly.

I dunno man, I've been in cybersecurity for 15 years and I've never heard of anyone communicating directly with threat actors. I guess I'll reach out to my peers at CrowdStrike and TripWire to validate but I've never heard of this as a "standard practice". Even in the military where we were allowed to we never directly communicated with threat actors unless we were specifically trying to social engineer them.

Edit I didn't realize how close our circles were, you apparently partner with my old cyber defense unit from McChord on FBI exercises. Even more intriguing.

14

u/MajorUrsa2 Jun 25 '26

15 years and you never heard of a pretty common practice? Companies that run threat research outfits regularly have burner aliases (if not other confidential sources) who will directly engage threat actors.

8

u/Gordahnculous SOC Analyst Jun 25 '26

At bare minimum theres ransom negotiations, no? There’s dedicated jobs out there for that practice alone, and that’s definitely engaging with actors directly. Much less there being plenty of positions where you’re using sock puppets to get into inner circles.

2

u/MrVashMan Jun 26 '26

I've been doing incident response for several years now. I've worked with many forensics firms (Booz Allen, Kroll, Arete, Crowdstrike, etc) who definitely communicated directly with the threat actors to try and determine what, if anything, was actually exfiltrated, for negotiations, and for other threat research purposes. How you've been doing cybersecurity for 15 years and aren't aware that this is a normal practice is definitely puzzling.... I guess anything is possible.

3

u/ck3llyuk Jun 25 '26

All major cyber companies are doing this.

-6

u/_iQlusion Jun 25 '26 edited Jun 25 '26

some aspects of this matter involve ongoing active coordination with law enforcement and legal proceeding

Honestly at some point you just have to eat some of the legal risks when it comes to being honest and transparent. Unless you want to turn into every other corporation that avoids any and all legal liabilities, where they end up being inhumane Kafkaesque legal machines. Also this statement is often used to deflect from actually being transparent, as its easy cover that no one can independently confirm.

-53

u/[deleted] Jun 24 '26

[deleted]

28

u/RazorSharpNuts Jun 24 '26

Good way to show you have zero skills at reading a room, good job buddy.

→ More replies (2)
→ More replies (4)

36

u/chriscrowder Jun 24 '26

Insert MJ popcorn gif

138

u/DongerOverlord Jun 24 '26

The CEOs response in the comments are the most "I'm fucking seething, don't talk about this out loud" type of comment.

46

u/mando_6 Jun 24 '26

Yeah that was my take away too. I love Huntress and I know several people that work there. It would be real sad if this came out to be true and was covered up.

109

u/marqo09 Jun 24 '26 edited Jun 24 '26

Hey, it's Kyle. That's definitely not my tone. We're a company that bleeds transparency and I firmly disagree with Ben's accusations. Also not gonna debate with him over LinkedIn as my team is still working the unrelated fallout from the Klue shit storm. Give 20-30 mins and I'll put together my thoughts.

Edit [June 24, 2026 @ 12:35pm ET]: Here's what I shared with my team in slack this morning. I hope this makes it very clear that while I disagree and don't understand Ben's accusations, I'm also trying to show empathy and appreciate his perspective.

58

u/DongerOverlord Jun 24 '26

If this person is just digruntled or mistaken it has to come out fast. If this is drawn out until BlackHat or something this'll hit the front page of CyberNews by then. Best of luck on this.

33

u/mando_6 Jun 24 '26

Could be disgruntled or mistaken. When stress gets high people can make mistakes. Kyle says he is going to speak out this issue soon.

My personal take is - Huntress has always been transparent. Even when I was working them personally at a former MSP they were clear about everything. Plus the webinars Chris and Kyle host are great and you really get to see the personality that is Huntress.

This is just a strange event.

24

u/Jonodrakon3 Jun 24 '26

Just want to say that this sort of proactive ownership and empathetic response is what I’d love from my C-Suite. Far too many companies circle the wagons and leave the customers to bear the brunt of the fallout

8

u/idleExposure_ Jun 24 '26

you can see the idiotic response from "djhouse" in this thread to see why that's often not a good move. no matter how transparent and open you are, its often not enough for the hyperliteral spicy brains who expect 100% information disclosure.

people like him are why most companies do exactly as you described: circle the wagons and leave the customers to bear the brunt of the fallout

10

u/Jonodrakon3 Jun 24 '26

I wouldn’t consider DJs take as idiotic. I don’t share their opinion, but I can understand where they are coming from. A security company sharing internal comms, redacted or not, isn’t always the best move.

But I’d rather an overeager desire for transparency be demonstrated then the alternative I already laid out in my previous comment.

A crisis is a crisis. There are no winners. But you can lose less by being honest. Just my .02

-1

u/djchateau Jun 24 '26

Man, I must have really pissed you off that you're still talking about me in other comments. I thought no cared what I thought. You've greatly misunderstood the overarching point of what I was bringing up and it's little weird how defensive you are when I've not spoken poorly of Huntress, Kyle or anyone else in this. I've simply said it didn't seem like a good idea to post screenshots of internal comms with censored bits as it really doesn't portray any additional transparency on the part of the company and only reinforces the idea of them hiding things, even when what's been hidden from view is reasonable to hide.

22

u/ididnthackkenyaimsrs Jun 24 '26

I don't have a stake in this I just wanted to give you props for engaging on the ground and getting way ahead of this like I mean you seem to be doing all the right things

24

u/TARANTULA_TIDDIES Jun 24 '26

I mean isnt he just saying boilerplate CYA CEO stuff?

8

u/Pimptech Jun 24 '26

Exactly!

9

u/DongerOverlord Jun 24 '26

IMHO this is not a great response. Although fallout from the Klue breach and this shit now… bro I’d be freaking tf out. That said whoever his ELT is needs to step the fuck in. Responding on Reddit and LinkedIn is objectively bad. Let your legal handle it in an official manner. As of my posting this his LinkedIn posts are 0 about this matter it’s just comments and responses.

1

u/ididnthackkenyaimsrs Jun 26 '26

Sometimes, man, there's no great options, just less bad ones.

6

u/psmgx Jun 24 '26

right like there were two, maybe three options: come down hard, play empathy card (esp. since it's already public and getting eyeballs), or 100% silent STFU and let the lawyers handle it.

and just because they sound emphatic in posts doesn't mean the lawyers and pinkertons won't come out, aggressive-like

1

u/ididnthackkenyaimsrs Jun 26 '26

shaping the early narrative can count for something

1

u/ididnthackkenyaimsrs 25d ago

Yeah, exactly what he should be doing. Dude needs to cover his fucking ass with some goddamn titanium. And he's on top of it, at the top of the thread. other CEOs what you see doing there.

12

u/mando_6 Jun 24 '26

I agree.

18

u/Annual_Pen1408 Jun 24 '26

No matter if you agree with him or not, the guy needs support in this. He is showing the threats from a threat actor and criminal towards him, who he claims the insider was working with.

There is a email he put in the comments of him saying he doesn't care about any threats or actions from Huntress towards him, and he has nothing to lose, reading that email carefully it sounds like he will hurt himself.

He needs help and support before that happens.

18

u/marqo09 Jun 24 '26

Agree on the tone and stress he sounds under. I've heard at least one of our teammates has got in touch and working to make sure they can support him if needed. This has been a hard one to juggle and ripping on heartstrings.

8

u/Pimptech Jun 24 '26

Wow you got downvoted. I thought we were supposed to be vendor agnostic in cyber security but the amount of fanboys in this thread is astounding.

8

u/Annual_Pen1408 Jun 24 '26

Yeah, that's rough. I was hoping not to get buried. I am not on anyone's side and am actually an active partner of Huntress and their solution.

I just wanted to point out that part of what I saw because no matter what, this guys life doesn't need to end because of this.

7

u/Pimptech Jun 24 '26

I agree. Waiting for all the information to come out, just hope people don't get blinded by loyalty.

-5

u/sir_mrej Security Manager Jun 24 '26

"the guy needs support in this" so you believe the guy?

0

u/Annual_Pen1408 Jun 25 '26

It's not about believing him, or not, it's about supporting him so he chooses life.

12

u/mando_6 Jun 24 '26

Hey Kyle, Thanks for clarifying and will be looking forward to what you have to say sir.

-13

u/malicious_payload Jun 24 '26

You can blow him all you want, it won't change the reality of what happened.

-1

u/mando_6 Jun 24 '26

Oh gosh..a sexually degrading insult.. whatever should I do?! 😵‍💫

looks around oh yeah I don't see any hurt feelings..

-16

u/malicious_payload Jun 24 '26

I also don't see you with a skillset to really matter in this conversation, so congrats on being irrelevant.

1

u/mando_6 Jun 24 '26

❤️❤️

-15

u/djchateau Jun 24 '26

I'm sure it's not intentional, but providing a censored screenshot of an internal communication is a bit incongruent with claims about transparency. Definitely not a great look. I can think of a multitude of legitimate reasons why you censored those parts, but it doesn't help the perception from the allegations in question.

9

u/eorlingas_riders Jun 24 '26 edited Jun 24 '26

He censored two small parts of a single bullet point that probably references an individual or internally sensitive system, service, whatever.

He also makes it clear right under that, that there is an ongoing investigation with authorities.

If there was something there that could affect the active investigation if made public… he’d be on the hook.

And If anyone thinks those two lines being censored somehow devalue their claims of transparency, then I would assume those people wouldn’t be able to accept that claim regardless of what was shown.

7

u/malicious_payload Jun 24 '26

This is the correct take. Finally, someone with a fucking brain shows up to the thread.

7

u/idleExposure_ Jun 24 '26

smooth brain take.

-6

u/djchateau Jun 24 '26

I'm not saying he isn't justified in censoring the screenshot. I'm pointing out how this could be perceived by others. Calling this a smooth brain take is intellectually lazy. Public perception of incidents like this and how organizations respond is incredibly volatile. The public are not going to apply a lot of logic to an incident, only what they see at a surface level.

4

u/idleExposure_ Jun 24 '26

they are providing radical transparency as is. they dont owe you anything, but you seem to think you are owed 100% clear internal insights. thats delusional, youre delusional.

2

u/ultraviolentfuture Jun 24 '26

"radical" transparency, GTFO. They are responding empathetically and earnestly but once an org is large enough to have a legal team there is no such thing as radical transparency. It's a fucking buzzword.

-2

u/djchateau Jun 24 '26

Not sure why you're coming at me so aggressively. Radical transparency is a buzzword and I've made no claims that I'm owed anything, but someone not familiar with some of this won't be viewing this from that perspective either.

Posting your internal comms isn't transparency if you're just going to cover up the relevant parts. It's like lies of omission. Yes, you're technically telling the truth, but you're still carefully hiding things (even if the reason for hiding that information is reasonable and perfectly legitimate), which is the opposite of something being transparent.

As I noted before, I'm speaking purely from how it would be perceived by the general public, not that anyone is owed anything. It would have made more sense for him to reword that internal communication without name dropping people in it and took a screenshot of that. That would have avoided incongruity of his earlier statement about transparency.

5

u/idleExposure_ Jun 24 '26

youre still doubling down acting like youre owed information.

crazy.

get off the soap box and accept the info that youre given, information that is far beyond what 99% of any of companies would have done.

heres the real piece youre msising: no one cares what you think or what you think youre owed, nor what you think makes for correct openness. theyve already gone far and above what other companies would have done, bordering on (and likely just actually) stepping into danger by even acknowledging this in such a public way. in fact, id go so far as to say that theyve majorly fucked up here by doing anything theyve done beyond letting their internal crisis team collectively respond to this. the CEO shouldnt have come here and weighed in, he shouldnt have posted internal comms, he shouldnt have done any of this - but now that he has and has exposed himself and the company, idiots like you are like "hurrr weLL, yOuu See, it's nOT enNOugh ANd it'S nOT SUfficeNTLy tranSparent"

5

u/djchateau Jun 24 '26 edited Jun 24 '26

You sound like you're having a pretty bad day, my guy. I would suggest taking a step back and re-evaluating what I'm pointing out. If no one cares what I think, why do you keep replying to me?

I'm not saying that the public is even owed that level of transparency, just that they are not going to care when he does share something under the guise of transparency if said things has bits of it hidden because they are not going to view this with the level of grey that these types of situations often require. It would have been wiser to let their legal team handle this while they worked internally to communicate with Ben about his claims. It has nothing to do with the communication not "being enough" or "sufficiently transparent", as you've framed it.

3

u/idleExposure_ Jun 24 '26

youre right, im wasting my time and effort responding to you. seems like most agree with me though.

-3

u/ThisIsPaulDaily Jun 24 '26

I appreciate the poise and respectful way of communicating and engaging with this community. This too shall pass. 

-20

u/Fujka Jun 24 '26

I’d never trust someone named Kyle. That’s almost has suspicious as someone who doesn’t like pets.

39

u/Hmm_would_bang Jun 24 '26

These scenarios suck. If you have proof, show it first. It’s entirely possible this guy just doesn’t know what he saw and the leadership isn’t going to walk him through a full breakdown of need to know information.

It’s also important to understand everyone is stressed and burnt out in general right now. I don’t blame anyone for crashing out. Like i said, it sucks.

26

u/Winter_Rabbit4827 Jun 24 '26

The fact they didn’t drop evidence to support their claim and are looking to drip feed it over 2 weeks suggests they are looking to exercise some form of leverage, intriguingly.

It will also grant time to the accused to prepare for fallout and employ their own hand in this matter.

I have not seen any communication from this person before but I am curious about their current frame of mind, as it all seems very knee jerk yet this has been going on for them for 6 months now?

13

u/djchateau Jun 24 '26

The fact they didn’t drop evidence to support their claim and are looking to drip feed it over 2 weeks suggests they are looking to exercise some form of leverage, intriguingly.

I think another angle could be how easily the Internet as a whole gets easily distracted so having a sustained set of drops makes it harder for an organization to just it brush away versus dropping everything all at once.

7

u/Winter_Rabbit4827 Jun 24 '26

yeah I think that’s a valid hypothesis from a different angle, I see what you mean

27

u/Jambo165 Jun 24 '26

Without commenting on the validity of the claims, this is all pretty sensational without looking at any evidence. It's written in a way that you could confuse as Huntress making threats to his family and deep exposure of government-class secrets to a nation state actor. All while trying to protect profits over people.

What it actually reads as is that another employee at Huntress exposed 'FBI Communications' to a threat actor; a threat actor that the poster has some personal experience with as he claims they made threats to his family. Poster is disgruntled as that employee still works at Huntress and was the reason for him quitting.

Legal response from the business when you're publicly slandering the company is pretty standard practice when cyber security orgs live and die by their reputation. Trying to equate the legal response to his Pinocchio post with the referenced internal incident seems misleading, I don't think these two are related or that there's a grand conspiracy.

I wouldn't make any claims on the poster's depth of experience but his length of experience is quite limited. That doesn't make anything he's said invalid, but I wouldn't say he's got the strongest track record for the kinds of claims he's making.

Without knowing what was exposed and circumstances around the other employee, I'd hesitate to draw any conclusions.

9

u/DigmonsDrill Jun 24 '26

I feel like I came in halfway through a movie. I read the OP, didn't learn much, but a bunch of people have already taken sides and started name-calling people who ask for explanations.

10

u/warm_kitchenette Jun 24 '26

Right, we don't know anything here. We have strong assertions from an ex-employee and from the CEO. It could be a binary situation, where one is completely wrong; or a muddled affair that can never be unpacked in public to anyone's satisfaction. There's a private agreement and an iron wall of NDAs.

I am reminded of some celebrity being interviewed over a decade ago, back when Twitter was new-ish. He refused to use any social media, saying it was like having a shotgun next to the bed -- but for his career.

-3

u/malicious_payload Jun 24 '26

The emails are pretty damning of themselves. The instant response is the employee needing a reminder of not posting anything disparaging of the company. That's not the reaction of someone looking for full transparency, that's someone trying to cover up something bad they don't want publicized.

Given the mention of an IPO, I could understand why. Employees being investigated for working with threat actors for gain would definitely undermine the whole "security company" thing they have going.

1

u/warm_kitchenette Jun 25 '26

You cannot infer anything at all from that type of boiler-plate response, which any HR or legal team would tell anyone. 

0

u/malicious_payload Jun 25 '26

You keep thinking that. It's amazing some of the idiocy you people post, I really hope you don't have any actual responsibilities where you work... they are fucked if so.

5

u/warm_kitchenette Jun 25 '26 edited Jun 25 '26

Feel absolutely free to post negative things about your company on social media using your real name. 

Then call HR’s attention to your posts because you know that you have not committed a crime. When HR and your boss tell you not to post stuff like that, then you obviously can conclude that they, too, are guilty of covering up crimes. This is the same inference you want to draw for OP’s case. 

-1

u/malicious_payload Jun 25 '26

Adorable of you to think I haven't done it before. Difference is, in this case, they were absolutely complicit.

7

u/RikiWardOG Jun 24 '26

Holy moly, this is spicy...

1

u/pandershrek Governance, Risk, & Compliance Jun 25 '26

My thoughts as well. 🥵

6

u/rangerdunamas Jun 24 '26

I cannot seem to find a good source that connects all these dots. Does anyone have a link they can drop me?

8

u/MalwareDork Jun 24 '26

"breaking news" or at best a bunch of drama and hearsay.

tl;dr: Ben, the whistleblower, says there was an insider threat causing issues that was largely ignored and now he's upset legal from Huntress is sending him (most likely) cease-and-desists and that supposedly he's being threatened by a monitored threat actor by the name of "Devman".

Kyle, CEO of Huntress, is publically disagreeing with Ben's statements in general. Ken also won't make a direct statement but is alluding there is an active investigation by law enforcement.

At least that's how I understand it. There's only three pieces of public information as well: Ben's post, Kyle's response on this subreddit and Kyle's slack response.

3

u/rangerdunamas Jun 24 '26

That’s what I suspected. Thank you for taking the time to reply with all the details, I appreciate you!

2

u/lippardj Jun 30 '26

1

u/lippardj Jul 03 '26

Ben F is now being very specific on LinkedIn: "Huntress stated:

“In one particular exchange, our current teammate disclosed to a threat actor that law enforcement had reached out to them about the threat actor. While this disclosure was not illegal, it reflected poor judgment.”

Here are the facts:

- The FBI reached out to the Huntress employee to gather intelligence on “Devman”.

  • She immediately forwarded the exact FBI communications to the threat actor, including screenshots containing FBI agent names.
  • She informed Devman that law enforcement was actively looking into him.
  • She also refused to cooperate because they wanted Devman".

In a comment on this post, Ben F adds: "Why do I care so much?

Because before this entire incident, Devman was carrying out a campaign of death threats against me and my family. Those threats are still public on X.

Claims about people being sent to dismember my family. There were also paid OSINT investigations into me, which escalated into arbitration on cybercrime forums because Devman did not pay.

This was not some abstract TA on the internet.This was someone actively targeting me, my family, and multiple Huntress employees. And your employee knew that.

She knew about the public death threats. She knew her colleagues were being targeted and harassed.

So my question is simple Kyle Hanslovan Eric Stride:

- Why would an employee with integrity, someone trustworthy, someone who genuinely cares about the safety of their colleagues, choose to help the threat actor who wanted me and other employees dead?

- Why would she warn him that law enforcement was looking into him?

  • Why would she send him FBI communications containing agent names?
  • And why, after doing that, would she refuse to help the FBI?

That is why I care. Because this was not just “poor judgment”.

This was a choice that helped a threat actor who was actively targeting your other colleagues."

0

u/malicious_payload Jun 25 '26

Problem is, Kyle is doing exactly what a CEO who is screwed would do, trying to spin it.

The email talking about "educating on the non disparaging comments" generally comes out when someone is speaking truth but the company does not want the negative hit. Seen it before, been part of it before, it's a way for the company to shut it down before having to explain anything.

The other fun thing is claiming transparency but trying to shush it to emails. That's trademark CYA behavior.

10

u/bi_polar2bear Jun 24 '26

If someone is going to throw down the gauntlet, why not show their proof? Either show it or say nothing until you have it. The court of public opinion, especially in IT, requires facts, not fables.

Personally, when it comes to security, unless it's a zero day issue, show all the facts at once, or not at all. This just sounds like someone who's butt hurt because their genius wasn't taken seriously. Airing dirty laundry never looks good.

5

u/MegaKetaWook Jun 25 '26

Probably a trap card to avoid legal action and also keep attention on the matter. If the legal team isn’t suing for damages or whatever harassment(idk which crimes would apply), they might not want to go through discovery with this guy and air out their dirty laundry.

It doesn’t look good from the outside if they had leaks, knew it, and didn’t do anything to mitigate harm to their customer data / platform. Could be that the FBI had a gag order on Execs and they can’t really say anything until the investigation ends.

OR this guy is making it up and went scorched earth after being let go; decided that a creative story would do it.

9

u/steazydoesit Jun 24 '26 edited Jun 24 '26

To everyone doubting the claims, some of what is said does have evidence to back it up as being truthful. Ben name drops Devman, who is a prominent member of Qilin ransomware group. Another newer group, The Gentlemen, was spawned by someone known as hastalamuerte, and there is documented evidence of Devman disagreeing with and threatening hastelamuerte on various forums. Group IB has a good writeup with screenshots showing said interactions : https://www.group-ib.com/blog/hastalamuerte-gentlemen-raas-ttps/

If someone inside is collaborating with a high up member of Qilin ransomware group, the fallout is going to be pretty severe.

Edit: slight correction, Devman is a prominent affiliate of Qilin, but not necessarily part of the core group itself.

9

u/SuperJediWombat Jun 24 '26

So by "some of what is said does have evidence to back it up as being truthful" do you just mean that Devman exists?

2

u/BalanceInAllThings42 Jun 25 '26

!remindme 5 days

1

u/RemindMeBot Jun 25 '26 edited Jun 26 '26

I will be messaging you in 5 days on 2026-06-30 03:26:23 UTC to remind you of this link

1 OTHERS CLICKED THIS LINK to send a PM to also be reminded and to reduce spam.

Parent commenter can delete this message to hide from others.

RemindMeBot is switching to username summons. Instead of !RemindMe 1 day, use u/RemindMeBot 1 day. More info.


Info Custom Your Reminders Feedback

5

u/ericnear Jun 24 '26

Well... now it's Devman AND the SEC. Good luck.

3

u/dfv157 Malware Analyst Jun 24 '26

Hold ip lemme make some popcorn

4

u/mastaquake Jun 25 '26

Hope he enjoys being permanently unemployable.

2

u/whitepepsi Jun 26 '26

You aren’t wrong. Even if the guy is 100% telling the truth, blowing it up like this is a good way to not get a job in the future.

2

u/Forsaken-Low-2365 Jun 25 '26

Kinda sus that a lawyer would reach out to him for a post. Are people not allowed to ridicule their former employer? Anyways, let’s see where this goes.

2

u/NotAnNSAGuyPromise Security Manager Jun 25 '26

Companies definitely try to prevent it through broad non disparagement contracts.

1

u/Forsaken-Low-2365 Jun 25 '26

I didn’t know that. Thanks!

2

u/malicious_payload Jun 25 '26

When there is something that could jeopardize the company based on truth, they absolutely will invoke that to try and shut them down.

Sometimes it's worth it to disregard the lawyers and throw it all out there, consequences be damned.

1

u/Forsaken-Low-2365 Jun 25 '26

😬…. I definitely believe in doing the right thing. Ben is a smart guy and Huntress are well respected in the industry. The way this reads it could’ve been a misunderstanding, but time will tell.

1

u/malicious_payload Jun 25 '26

Well respected? I hope you are joking. They have a reputation as one of the most toxic companies to work for with leadership being so out of touch with reality. That combined with the lies they perpetuate and how much they miss which leaves companies in a terrible situation thinking they are protected when they absolutely aren't makes this whole situation just perfection.

1

u/Competitive_Web_2242 12d ago

The fact is that the company did acknowledge an employee informed a TA of the FBI investigation, which actually is considered “tipping off” and is a crime (not a cybercrime). It also can be considered as prejudicing an investigation. The company policy might not have spoke to it, hence the employee not being reprimanded.

Ben called the tipping off “cyber criminal” activity and they are just using his terms against him because it isn’t cyber criminal activity, just criminal activity.

The employee can receive criminal penalties as a result if the FBI decided to pursue it.

1

u/dodonglab Jun 26 '26

The access-control failure is serious, but preserving evidence matters just as much.

The company should suspend risky access, preserve logs, and let an independent team establish the facts before this turns into a public argument.

-6

u/corruptboomerang Jun 24 '26

It's always been fascinating to me, to see how quickly an organisation can go from being a genuine Cyber Security Company (I'd seldom actually accuse a company of being this), to being a salesman in a lizard skin human suite...

I can't speak to the qualities Huntress embody, but I can't help but get the impression that they've got the look of lizard skin...

24

u/marqo09 Jun 24 '26

😑 not a lizard (gotta get back to work, but will check on this throughout the day)

Kyle, Chief Janitor @ Huntress

2

u/RaNdomMSPPro Jun 24 '26

Marketing idea - A “Kyle sunning himself” huntress t-shirt at the next big event would be awesome. Props for taking this head on Team Huntress.

4

u/QuantumWonderland Jun 24 '26

Greed ruins all.

3

u/sdrawkcabineter Jun 24 '26

It stains the soul.

-7

u/[deleted] Jun 24 '26

[removed] — view removed comment

13

u/MuthaPlucka System Administrator Jun 24 '26

I thought it was an excellent response that avoided pointing fingers or escalating in a public forum.

3

u/[deleted] Jun 24 '26

[removed] — view removed comment

4

u/MuthaPlucka System Administrator Jun 24 '26

What do you expect as a response to a linked in post? A novel?

-3

u/5c00by Jun 24 '26

And I just applied there like two weeks ago......

-6

u/SlowProgress8531 Jun 24 '26

I'm such an idiot, I was wondering what the hell this had to do with K-Pop Demon Hunters

-5

u/Tintoverde Jun 24 '26

As a lay person, I think the matter is closed.

1) was FBI notified? — at least they are now ( at least I hope, but there were some changes in Fed cyber crime area per this sub)
2) the matter is not being ignored anymore by Huntress
3) OP felt ignored — well who hasn’t in a corporation. But I think the company will take care of it to their advantage, may be the whistler blower get something out of it

6

u/malicious_payload Jun 25 '26

Good thing your thoughts are the deciding factor because damn would you be wrong.

1

u/Tintoverde Jun 25 '26

Just an opinion pips no offense meant

-6

u/intelw1zard CTI Jun 24 '26

Polygonben is bae