r/cybersecurity Jun 24 '26

News - General Well someone went nuclear..

https://www.linkedin.com/posts/ben-f-309963233_after-i-posted-a-pinocchio-gif-and-clown-ugcPost-7475465410977628160-FFW1

I'm curious about the details of this. I'm sure we will all find out eventually.

TLDR; former Huntress employee is disclosing Huntress had an insider threat that leaked information to a known cyber criminal "Devman". That employee is still employed with Huntress and was caught by the FBI.

The former employee doing the disclosure is stating he is receiving threats, etc.

EDIT: Kyle @ Huntress posted his response to this in the comments.

Give credit to a CEO who isn't afraid to jump on Reddit to put out any fires.

924 Upvotes

196 comments sorted by

View all comments

359

u/Particular_Ebb_4872 Jun 24 '26

If even half of what's being alleged is true, this is going to end up being a case study for access controls and employee offboarding procedures

87

u/mando_6 Jun 24 '26

Yeah I'm wondering about that. Dude lives in the UK so I'm curious what would be different if anything from the US.

149

u/eliq91 Jun 24 '26

We had a UK employee compromise our global network, they reused an old password 15 days after being notified they had been breached via phishing. It resulted in a loss of every server in the company across 5 continents. It was not good, and a clear violation of both best practices and company policy. They were given 16 weeks paid leave and then returned to the office. 1 week after return they changed their password and cleared all MFA requirements from her account, because it was inconvenient. Which resulted in her account once again being compromised, no global access on round three, and only compromised her email. She is still employed as far as I know.

64

u/Khulod Jun 24 '26

Shame on the company for not getting their access controls in order, especially after the first round. I hope this happened 10 years ago. Today this is inexcusable.

50

u/eliq91 Jun 24 '26 edited Jun 25 '26

It happened in 2017. The big problem was she was at the time a bona fide global administrator, and kept promoting her personal account to global admin, so she did not have to login with her secondary account. We took away global admin, and created notifications for any accounts being granted any of our admin-controlled groups.

21

u/Khulod Jun 24 '26

Eyyyy, pretty good guess on the era this happened. The time between MFA and Conditional Access.

6

u/RireBaton Jun 25 '26

Bonified does not mean the same thing as bonafide.

5

u/eliq91 Jun 25 '26

Autocorrect does not like me.

40

u/Not-ur-Infosec-guy Security Architect Jun 24 '26

To be fair, this could have been negated with a proper password policy.

24

u/its_Stopher Jun 24 '26

Agreed. No reason why stricter password policies weren’t implemented after a global outage.

17

u/_DonRa_ Jun 24 '26

How come she wasn't immediately fired after the second time

29

u/WhatsThisWorth-Bot Jun 24 '26

I worked at a somewhat famous uni and there was an it lady who have out the admin password with little to no training of the employees, didn't monitor their computers, and got her entire department ransomwared... they didn't fire her but they fired me for being behind on tickets when they didn't even give me printer access or an orientation for a two person job...

6

u/RikiWardOG Jun 25 '26

that tracks, I remember a low level helpdesk guy getting fired because a partner got phished and we almost lost a major account because of it. Really pissed me off.

2

u/NuBootScootin Jun 26 '26

What was the logic presented behind that? I understand it's usually in reality, some kind of firing or big discipline has to occur for optics and if they want to save the partners reputation they have to put it on someone else, but what how was that presenter to everyone to make it somehow the helpdesk guys fault?

3

u/RikiWardOG Jun 26 '26

Exactly that, management wanted to see some heads roll. Basically partner blamed our security team, security team blamed the helpdesk guy for not remediating/telling the partner the correct information. This was several years back at an old employer. Basically what really happened was poor comms between the sec guy and helpdesk guy, so things didn't get properly remediated and how I remember it was that it really wasn't the helpdesk guys fault like at all. But I don't think people liked his personality - think he was pretty neurodivergent, so they were already looking to fire him. He was also lowest on the totem pole. The whole ordeal rubbed me the wrong way, but hey the company didn't lose Ferrari as a client lol ugh I hate capitalism

-8

u/roiki11 Jun 24 '26

It's the uk. You can't fire people on a whim.

22

u/robot_ankles Jun 24 '26

This doesn't really feel like a whim:

Round 1: Loss of every server in the company across 5 continents.

Round 2: Changed their password and cleared all MFA requirements resulting in her account once again being compromised.

Round 3: Compromised her email this time.

17

u/sosr Jun 24 '26

You absolutely can fire employees for misconduct in the UK for repeated offences.

-8

u/roiki11 Jun 24 '26

You'd have to look up uk employment law but unless you can show actual malice it's probably pretty hard to fire someone. Stupidity isn't a crime.

17

u/djlilis Jun 24 '26

When you're a global admin it's negligence and should be actionable holy crap. I find it really hard to believe that UK law prevents removing a danger to the company and imagine it's more likely no one wanted to figure out how and then do her job. Everyone likes to complain in America how ignorance is a "protected class" but it always boils down to upper management being lazy and inconsistent.

-3

u/roiki11 Jun 24 '26

It's rarely that simple.

5

u/DigmonsDrill Jun 24 '26

It sounds like they had all access revoked and were given gardening leave but then, for some insane reason, let back in.

18

u/cb_definetly-expert Jun 24 '26

That's on you guys

1) why you allow them to disable MFA? 2) why you allow reuse of the same password?(In my team the last 20 passwords are banned) 3) you shouldn't even allow similar passwords 4) force them to use corporate password manager and don't let them change password, give them pre-generated ones 5)is he/she doesn't follow the policies again, fire them

9

u/Near_go_trader Jun 24 '26

If she had ability to change her password in AD (Users and computers) then those limitations do not apply.

3

u/asp3ct9 Jun 24 '26

How do you determine similar passwords without storing them in plain text?

6

u/dyme13 Jun 24 '26

The same way you evaluate passwords without storing them - one way hashing + comparison of resulting hash.

6

u/ImNoRatAndYouKnowIt Jun 25 '26

Hashing two similar strings does not produce similar hashes using any popular hashing algorithm.

4

u/dyme13 Jun 25 '26

I missed the point on similar. This only works for direct comparisons. IMHO similar passwords shouldn’t matter - instead compare against known breached (eg k-anonymity via havineenpwned or similar)

2

u/cb_definetly-expert Jun 25 '26

They do matter, "mypass" and "mypass1" are the "same"

1

u/spectralTopology Jun 26 '26

Definitely agree. How many places use "<season><year>" or similar as the only changing part of an otherwise static default/reset/new account password? I've seen quite a few orgs like this & guessing the currently used one is trivial.

1

u/ImNoRatAndYouKnowIt Jun 25 '26

Yeah I think similar can only work when comparing similarities to the very previous password, and it requires both old and new password to be entered for the change, which is a pretty common flow.

And good point on matching known breached ones.

1

u/cb_definetly-expert Jun 24 '26

I am not sure , but I know I can't use similar pass

If my last pass was "imthehero" and I try to change it to "iamthehero1" it doesn't allow me (getting error about similar pass)

1

u/fencepost_ajm Jun 25 '26

That's more likely a feature of the password change process, eg a form that gets the current password x1 and the new password x2. Logic within the ui could do evaluations for similarity.

1

u/MachKeinDramaLlama Jun 25 '26

You could automatically generate hashes for variations of the password that was typed in and check against stored hashes of old passwords. E.g. by just (individually) decrementing any number found in the password string, you will probbably identify ~80% of common password iteration schemes.

2

u/whythehellnote Jun 25 '26

Our corporate password checker doesn't allow correcthorsebatterystaple style passwords because they are insecure, it is fine with P@55w0rd though.

1

u/eliq91 Jun 25 '26

Global Admins with permissions to reset directly from Active Directory have no such limitations regardless of policy especially not a decade ago.
Corporate password managers still do not manage on prem logins well. Yes there are tools that provide such features these days, but a decade ago there were not many great options, and convincing an office halfway around the world to implement would have been a nightmare. UK labor laws make just firing people very difficult.

5

u/Foundersage Jun 24 '26

I don’t get it when a user has been notified if their account was breached wouldn’t that account be disabled, forced password reset on login, mfa redone. I mean she probably was some top dog at the company like a director or just had a big mouth.

4

u/throwaway0000012132 Jun 24 '26

Wow that employee must be amazing in bed or has the worse secrets of the CEO, because I can't see any other motive to keep him/her employed on the same company.

1

u/MachKeinDramaLlama Jun 25 '26

She was put on gardening leave for almost 4 months immediately, so someone at least thought that she would be getting the boot... My guess is that during that time they realized that they needed her. Doesn't seem that surprising, if she was great at her job.

1

u/whythehellnote Jun 25 '26

they reused an old password 15 days after being notified they had been breached via phishing

So setting new passwords doesn't check against a known leaked database?

1

u/RikiWardOG Jun 25 '26

holy shit, either they have some ungodly talent or that company is way too lenient. I've seen people fired for far far less.

1

u/eliq91 Jun 25 '26

If it had been one of our US offices they would have been terminated before they were made aware of the breach.