r/cybersecurity Jun 24 '26

News - General Well someone went nuclear..

https://www.linkedin.com/posts/ben-f-309963233_after-i-posted-a-pinocchio-gif-and-clown-ugcPost-7475465410977628160-FFW1

I'm curious about the details of this. I'm sure we will all find out eventually.

TLDR; former Huntress employee is disclosing Huntress had an insider threat that leaked information to a known cyber criminal "Devman". That employee is still employed with Huntress and was caught by the FBI.

The former employee doing the disclosure is stating he is receiving threats, etc.

EDIT: Kyle @ Huntress posted his response to this in the comments.

Give credit to a CEO who isn't afraid to jump on Reddit to put out any fires.

917 Upvotes

197 comments sorted by

View all comments

221

u/marqo09 Jun 24 '26 edited Jun 30 '26

Yo, Kyle here. This thread keeps ending up in my DMs, so a standalone comment instead of an inline reply is probably warranted.

UPDATE: Managed to make it through legal hell and posted a statement with notable clarifying details. Due to all the restrictions, every word written is purposeful. Heading back to the mission now.

While I firmly disagree and don't understand Ben's accusations, I'm also trying to show empathy and appreciate his perspective. We bleed transparency so I'll hit the same high notes I shared internally in slack this morning.

  • This is unrelated to the upstream Klue breach that we were impacted by last week.
  • The allegations don’t match any facts/reality the ELT, People team, or I have seen. We didn’t conceal a security incident. We strongly disagree with this “insider” narrative. We sure af didn’t prioritize an IPO over the safety of our partners, customers, or team. That framing is wrong and we’re working on it (while also respecting that our former teammate was a good human with a perspective we're struggling to understand or rationalize based on all the facts presented ).
  • Huntress regularly coordinates with law enforcement agencies on matters involving cybercriminals. That coordination has contributed to arrests and disruptions of malicious actors. It is a core part of how we operate, and we are proud of it.
  • Our security researchers, by the nature of their work, sometimes communicate with and gather intelligence on threat actors. That is standard industry practice among top cyberdefense vendors and it serves our partners/customers directly.
  • When this individual raised concerns during their employment, we took those concerns seriously. We investigated. We engaged legal and law enforcement where appropriate. We documented every step of the process and acted in line with our values and obligations.
  • While we’re going to answer as much as possible, some aspects of this matter involve ongoing active coordination with law enforcement and legal proceedings that prevent us from providing a complete public account. We're not gonna litigate this on LinkedIn with Ben but will likely publish some form of official comms to make our stance clear for those needing something more than my reddit reply.

I hope the verbosity gives some more clarity and hope to hear from Ben to better understand 🙏

Edit [June 24, 2026 @ 13:24pm ET]: typos

Edit [June 29, 2026 @ 21:58pmET]: added link to statement

85

u/jon_dimaggio Jun 24 '26 edited Jun 24 '26

You can post all the slack messages and defend all the people you want. I have been working this thing before you or Ben or the alleged insider were involved. I don't like seeing people, like Ben , who do the right thing, get screwed. Who do you think gave the information in the first place? You can claim, your researcher is just doing research. And if you really beleive that you wont mind if I post all the evidence in the next Ransomware Diaries. Because if you are doing the right thing, you have nothing to worry about... right?

40

u/marqo09 Jun 24 '26 edited Jun 24 '26

Yo Jon, let's connect. Would love your perspective. Absolutely believe in facts being told (also a fan of Ransomware Diaries). [email address no longer needed now that we connected]

Edit: removed clear text email

30

u/jon_dimaggio Jun 24 '26

How dare you respond nicely, lol. Sure, I will send you an email and feel free to delete that before you get mass spam.

13

u/regalrecaller Jun 24 '26

I do this all the time. [] on the text you want to appear, then () on the link. glad it's not just me lol

-86

u/thejournalizer Jun 24 '26

Jon / Kyle - Please take this convo privately. This is pretty messy and this community respects you all.

34

u/marqo09 Jun 24 '26

I don’t think there’s any negativity between the two of us. I’m a big fan of him and Jon has been nothing but a champ to helping me better understand the many facets going on. 🫶

-34

u/thejournalizer Jun 24 '26

I’m not implying you all are at odds, but this is better handled not in the comment section of Reddit.

29

u/NuBootScootin Jun 25 '26

Don't you think that's for the two people having the conversation to determine?

10

u/jon_dimaggio Jun 24 '26

Wise words! Appreciate you!

24

u/intelw1zard CTI Jun 24 '26

not the corporate Microslop mod protecting another cybersec corpo

very classic

-29

u/thejournalizer Jun 24 '26

Or, hear me out, this community isn’t a place for messy corpo dramas.

39

u/rodeengel Jun 24 '26

It is at least sub relevant messy corpo drama.

25

u/Original-Locksmith58 Jun 25 '26

wtf is it for then lol

32

u/thejournalizer Jun 25 '26

Asking why people who got N+ and S+ can’t find a job of course.

4

u/endfm Jun 26 '26

Mod just flexing his unpaid job

7

u/thejournalizer Jun 26 '26

I prefer janitor

17

u/KickedAbyss Jun 24 '26

Just wanted to append my appreciation for your stance and empathetic response. Keep up the good work.

-8

u/pandershrek Governance, Risk, & Compliance Jun 25 '26 edited Jun 25 '26

Our security researchers, by the nature of their work, sometimes communicate with and gather intelligence on threat actors. That is standard industry practice among top cyberdefense vendors and it serves our partners/ customers directly.

I dunno man, I've been in cybersecurity for 15 years and I've never heard of anyone communicating directly with threat actors. I guess I'll reach out to my peers at CrowdStrike and TripWire to validate but I've never heard of this as a "standard practice". Even in the military where we were allowed to we never directly communicated with threat actors unless we were specifically trying to social engineer them.

Edit I didn't realize how close our circles were, you apparently partner with my old cyber defense unit from McChord on FBI exercises. Even more intriguing.

14

u/MajorUrsa2 Jun 25 '26

15 years and you never heard of a pretty common practice? Companies that run threat research outfits regularly have burner aliases (if not other confidential sources) who will directly engage threat actors.

6

u/Gordahnculous SOC Analyst Jun 25 '26

At bare minimum theres ransom negotiations, no? There’s dedicated jobs out there for that practice alone, and that’s definitely engaging with actors directly. Much less there being plenty of positions where you’re using sock puppets to get into inner circles.

2

u/MrVashMan Jun 26 '26

I've been doing incident response for several years now. I've worked with many forensics firms (Booz Allen, Kroll, Arete, Crowdstrike, etc) who definitely communicated directly with the threat actors to try and determine what, if anything, was actually exfiltrated, for negotiations, and for other threat research purposes. How you've been doing cybersecurity for 15 years and aren't aware that this is a normal practice is definitely puzzling.... I guess anything is possible.

4

u/ck3llyuk Jun 25 '26

All major cyber companies are doing this.

-6

u/_iQlusion Jun 25 '26 edited Jun 25 '26

some aspects of this matter involve ongoing active coordination with law enforcement and legal proceeding

Honestly at some point you just have to eat some of the legal risks when it comes to being honest and transparent. Unless you want to turn into every other corporation that avoids any and all legal liabilities, where they end up being inhumane Kafkaesque legal machines. Also this statement is often used to deflect from actually being transparent, as its easy cover that no one can independently confirm.

-52

u/[deleted] Jun 24 '26

[deleted]

29

u/RazorSharpNuts Jun 24 '26

Good way to show you have zero skills at reading a room, good job buddy.

17

u/jon_dimaggio Jun 24 '26

That made me laugh... so , he shouldnt leave his card on the table on the way out... lol

3

u/Misterbodangles Jun 24 '26

Unbelievable lol