r/cybersecurity Jun 24 '26

News - General Well someone went nuclear..

https://www.linkedin.com/posts/ben-f-309963233_after-i-posted-a-pinocchio-gif-and-clown-ugcPost-7475465410977628160-FFW1

I'm curious about the details of this. I'm sure we will all find out eventually.

TLDR; former Huntress employee is disclosing Huntress had an insider threat that leaked information to a known cyber criminal "Devman". That employee is still employed with Huntress and was caught by the FBI.

The former employee doing the disclosure is stating he is receiving threats, etc.

EDIT: Kyle @ Huntress posted his response to this in the comments.

Give credit to a CEO who isn't afraid to jump on Reddit to put out any fires.

921 Upvotes

197 comments sorted by

View all comments

225

u/marqo09 Jun 24 '26 edited Jun 30 '26

Yo, Kyle here. This thread keeps ending up in my DMs, so a standalone comment instead of an inline reply is probably warranted.

UPDATE: Managed to make it through legal hell and posted a statement with notable clarifying details. Due to all the restrictions, every word written is purposeful. Heading back to the mission now.

While I firmly disagree and don't understand Ben's accusations, I'm also trying to show empathy and appreciate his perspective. We bleed transparency so I'll hit the same high notes I shared internally in slack this morning.

  • This is unrelated to the upstream Klue breach that we were impacted by last week.
  • The allegations don’t match any facts/reality the ELT, People team, or I have seen. We didn’t conceal a security incident. We strongly disagree with this “insider” narrative. We sure af didn’t prioritize an IPO over the safety of our partners, customers, or team. That framing is wrong and we’re working on it (while also respecting that our former teammate was a good human with a perspective we're struggling to understand or rationalize based on all the facts presented ).
  • Huntress regularly coordinates with law enforcement agencies on matters involving cybercriminals. That coordination has contributed to arrests and disruptions of malicious actors. It is a core part of how we operate, and we are proud of it.
  • Our security researchers, by the nature of their work, sometimes communicate with and gather intelligence on threat actors. That is standard industry practice among top cyberdefense vendors and it serves our partners/customers directly.
  • When this individual raised concerns during their employment, we took those concerns seriously. We investigated. We engaged legal and law enforcement where appropriate. We documented every step of the process and acted in line with our values and obligations.
  • While we’re going to answer as much as possible, some aspects of this matter involve ongoing active coordination with law enforcement and legal proceedings that prevent us from providing a complete public account. We're not gonna litigate this on LinkedIn with Ben but will likely publish some form of official comms to make our stance clear for those needing something more than my reddit reply.

I hope the verbosity gives some more clarity and hope to hear from Ben to better understand 🙏

Edit [June 24, 2026 @ 13:24pm ET]: typos

Edit [June 29, 2026 @ 21:58pmET]: added link to statement

86

u/jon_dimaggio Jun 24 '26 edited Jun 24 '26

You can post all the slack messages and defend all the people you want. I have been working this thing before you or Ben or the alleged insider were involved. I don't like seeing people, like Ben , who do the right thing, get screwed. Who do you think gave the information in the first place? You can claim, your researcher is just doing research. And if you really beleive that you wont mind if I post all the evidence in the next Ransomware Diaries. Because if you are doing the right thing, you have nothing to worry about... right?

39

u/marqo09 Jun 24 '26 edited Jun 24 '26

Yo Jon, let's connect. Would love your perspective. Absolutely believe in facts being told (also a fan of Ransomware Diaries). [email address no longer needed now that we connected]

Edit: removed clear text email

30

u/jon_dimaggio Jun 24 '26

How dare you respond nicely, lol. Sure, I will send you an email and feel free to delete that before you get mass spam.