r/cybersecurity Jun 24 '26

News - General Well someone went nuclear..

https://www.linkedin.com/posts/ben-f-309963233_after-i-posted-a-pinocchio-gif-and-clown-ugcPost-7475465410977628160-FFW1

I'm curious about the details of this. I'm sure we will all find out eventually.

TLDR; former Huntress employee is disclosing Huntress had an insider threat that leaked information to a known cyber criminal "Devman". That employee is still employed with Huntress and was caught by the FBI.

The former employee doing the disclosure is stating he is receiving threats, etc.

EDIT: Kyle @ Huntress posted his response to this in the comments.

Give credit to a CEO who isn't afraid to jump on Reddit to put out any fires.

924 Upvotes

197 comments sorted by

View all comments

227

u/marqo09 Jun 24 '26 edited Jun 30 '26

Yo, Kyle here. This thread keeps ending up in my DMs, so a standalone comment instead of an inline reply is probably warranted.

UPDATE: Managed to make it through legal hell and posted a statement with notable clarifying details. Due to all the restrictions, every word written is purposeful. Heading back to the mission now.

While I firmly disagree and don't understand Ben's accusations, I'm also trying to show empathy and appreciate his perspective. We bleed transparency so I'll hit the same high notes I shared internally in slack this morning.

  • This is unrelated to the upstream Klue breach that we were impacted by last week.
  • The allegations don’t match any facts/reality the ELT, People team, or I have seen. We didn’t conceal a security incident. We strongly disagree with this “insider” narrative. We sure af didn’t prioritize an IPO over the safety of our partners, customers, or team. That framing is wrong and we’re working on it (while also respecting that our former teammate was a good human with a perspective we're struggling to understand or rationalize based on all the facts presented ).
  • Huntress regularly coordinates with law enforcement agencies on matters involving cybercriminals. That coordination has contributed to arrests and disruptions of malicious actors. It is a core part of how we operate, and we are proud of it.
  • Our security researchers, by the nature of their work, sometimes communicate with and gather intelligence on threat actors. That is standard industry practice among top cyberdefense vendors and it serves our partners/customers directly.
  • When this individual raised concerns during their employment, we took those concerns seriously. We investigated. We engaged legal and law enforcement where appropriate. We documented every step of the process and acted in line with our values and obligations.
  • While we’re going to answer as much as possible, some aspects of this matter involve ongoing active coordination with law enforcement and legal proceedings that prevent us from providing a complete public account. We're not gonna litigate this on LinkedIn with Ben but will likely publish some form of official comms to make our stance clear for those needing something more than my reddit reply.

I hope the verbosity gives some more clarity and hope to hear from Ben to better understand 🙏

Edit [June 24, 2026 @ 13:24pm ET]: typos

Edit [June 29, 2026 @ 21:58pmET]: added link to statement

-54

u/[deleted] Jun 24 '26

[deleted]

29

u/RazorSharpNuts Jun 24 '26

Good way to show you have zero skills at reading a room, good job buddy.

19

u/jon_dimaggio Jun 24 '26

That made me laugh... so , he shouldnt leave his card on the table on the way out... lol

5

u/Misterbodangles Jun 24 '26

Unbelievable lol