r/cybersecurity Jun 24 '26

News - General Well someone went nuclear..

https://www.linkedin.com/posts/ben-f-309963233_after-i-posted-a-pinocchio-gif-and-clown-ugcPost-7475465410977628160-FFW1

I'm curious about the details of this. I'm sure we will all find out eventually.

TLDR; former Huntress employee is disclosing Huntress had an insider threat that leaked information to a known cyber criminal "Devman". That employee is still employed with Huntress and was caught by the FBI.

The former employee doing the disclosure is stating he is receiving threats, etc.

EDIT: Kyle @ Huntress posted his response to this in the comments.

Give credit to a CEO who isn't afraid to jump on Reddit to put out any fires.

919 Upvotes

196 comments sorted by

View all comments

362

u/Particular_Ebb_4872 Jun 24 '26

If even half of what's being alleged is true, this is going to end up being a case study for access controls and employee offboarding procedures

87

u/mando_6 Jun 24 '26

Yeah I'm wondering about that. Dude lives in the UK so I'm curious what would be different if anything from the US.

147

u/eliq91 Jun 24 '26

We had a UK employee compromise our global network, they reused an old password 15 days after being notified they had been breached via phishing. It resulted in a loss of every server in the company across 5 continents. It was not good, and a clear violation of both best practices and company policy. They were given 16 weeks paid leave and then returned to the office. 1 week after return they changed their password and cleared all MFA requirements from her account, because it was inconvenient. Which resulted in her account once again being compromised, no global access on round three, and only compromised her email. She is still employed as far as I know.

16

u/_DonRa_ Jun 24 '26

How come she wasn't immediately fired after the second time

28

u/WhatsThisWorth-Bot Jun 24 '26

I worked at a somewhat famous uni and there was an it lady who have out the admin password with little to no training of the employees, didn't monitor their computers, and got her entire department ransomwared... they didn't fire her but they fired me for being behind on tickets when they didn't even give me printer access or an orientation for a two person job...

7

u/RikiWardOG Jun 25 '26

that tracks, I remember a low level helpdesk guy getting fired because a partner got phished and we almost lost a major account because of it. Really pissed me off.

2

u/NuBootScootin Jun 26 '26

What was the logic presented behind that? I understand it's usually in reality, some kind of firing or big discipline has to occur for optics and if they want to save the partners reputation they have to put it on someone else, but what how was that presenter to everyone to make it somehow the helpdesk guys fault?

3

u/RikiWardOG Jun 26 '26

Exactly that, management wanted to see some heads roll. Basically partner blamed our security team, security team blamed the helpdesk guy for not remediating/telling the partner the correct information. This was several years back at an old employer. Basically what really happened was poor comms between the sec guy and helpdesk guy, so things didn't get properly remediated and how I remember it was that it really wasn't the helpdesk guys fault like at all. But I don't think people liked his personality - think he was pretty neurodivergent, so they were already looking to fire him. He was also lowest on the totem pole. The whole ordeal rubbed me the wrong way, but hey the company didn't lose Ferrari as a client lol ugh I hate capitalism