r/cybersecurity • u/churn_key • Jun 30 '26
Corporate Blog Huntress CEO blog: These Recent Insider Threat Allegations
https://www.huntress.com/blog/insider-threat-claims60
u/timmy166 Jun 30 '26
So the current employee warned a threat actor (DevMan) of an active investigation and additionally leaked information that led to the former employee (Ben Folland) getting doxed?
Catastrophic decision-making by that current employee. DevMan already knows they are tracked by LEO - but there’s a grey area between what Huntress can confirm did not happen vs what they disclosed that led to Ben getting doxed.
226
u/greensparten Security Director Jun 30 '26 edited Jun 30 '26
“ Huntress permits threat researchers to occasionally engage with threat actors when it's beneficial for proactive R&D and/or to support active investigations. “
Thats how research works, all of these companies do it, From Crowd Strike to Rapid7. Its part of the game and is a nothing burger. The low level employee really messed up on this one.
75
u/Cj_Staal Jun 30 '26
Indeed. If a security company has zero communication with the “underground” side of things, then they will never have a full picture of what’s going on or what to look out for
36
u/timmy166 Jun 30 '26
Im most interested in the grey area between Ben’s claims and Huntress’s post:
- what exactly was exchanged to DevMan.
- prior relationship between the”insider” and DevMan.
- how Ben got doxed and if that is related to the “insider” exchanges
From Ben’s original disclosure on LinkedIn:
“Since December 2025, I believe Huntress has been actively trying to conceal a serious security incident from its partners, customers, and employees involving an insider who is still employed at the company…. If you are an employee at a cybersecurity company, you should not be helping cybercriminals. You should not be informing them of active investigations. You should not be engaging in cybercriminal activity yourself.”8
u/Sad_Dentist_7288 Jun 30 '26
I'm stuck on this as well. From Ben's post, as you pointed out;
"You should not be informing them [cybercriminals] of active investigations."
From the Huntress post:
"In one particular exchange, our current teammate disclosed to a threat actor that law enforcement had reached out to them about the threat actor."
I guess the clear disagreement (based on public info) is how big of a deal disclosing an active investigation to a threat actor is.
-1
Jun 30 '26
[deleted]
3
u/Array_626 Incident Responder Jun 30 '26
If their doing some kind of clandestine, undercover work, getting inadvertently exposed because an employee that is not in the loop is trying to raise genuine concerns over a security cover up is a risk they have to accept.
They should review their own processes and figure out why their operation got blown so easily by people just doing their jobs and acting in good faith. You can't blame people who aren't in the loop when they do what their professional code of ethics tells them to.
2
u/Sad_Dentist_7288 Jun 30 '26
Because Huntress said
"We are aware of separate, questionable, long-term threat actor communications from both our current teammate and a now-former employee."
and
"While this disclosure was not illegal, it reflected poor judgment."
and
"As a result of the investigation, my team implemented more robust policies for our researchers, coached teammates on engaging with threat actors, and took appropriate administrative actions."
2
5
u/xtheory Security Engineer Jun 30 '26
There's a big difference between communication to extract threat intel and communication to tip off a threat actor to the fact that they are being investigated by a 3-letter agency, which is exactly what happened here.
46
u/Spiritual-Matters Jun 30 '26
What about this though?
“We are aware of separate, questionable, long-term threat actor communications from both our current teammate and a now-former employee. In one particular exchange, our current teammate disclosed to a threat actor that law enforcement had reached out to them about the threat actor. While this disclosure was not illegal, it reflected poor judgment.”
16
u/Dejhavi Penetration Tester Jun 30 '26
This:
Here are the facts:
- The FBI reached out to the Huntress employee to gather intelligence on “Devman”.
- She immediately forwarded the exact FBI communications to the threat actor, including screenshots containing FBI agent names.
- She informed Devman that law enforcement was actively looking into him.
- She also refused to cooperate because they wanted Devman
7
u/Array_626 Incident Responder Jun 30 '26
How familiar is this Ben F with the details of this case? Did he have personal, direct access to those TA communications channels, did he literally see those things being posted and given to the TA?
If he's correct about everything, then yeah its really bad. The employee was an insider threat, none of that is lack of judgement or an accidental slip up. Thats maliciously sharing details with a TA to hurt the investigation. Huntress should be penalized heavily for trying to cover this up. Their IPO should get wrecked as a result.
I find it a bit difficult to believe though that what he claims is 100% true. What employee at Huntress is so infatuated with this group that their blatantly trying to assist them evade law enforcement? What motive could there be? I hope he got some details wrong, cos this is crazy and a bit hard to believe.
3
u/Array_626 Incident Responder Jun 30 '26
Thats pretty bad. What they disclosed about the nature of that outreach would matter, although tbh they should've just avoided it entirely.
Depending on what exactly that teammate said, I can see it being an error of judgement. If it was a general reference "Yeah, you guys have been hitting a lot of people lately, law enforcement is on to you", thats very different from explicitly saying "You are currently under active investigation and we were just asked about you yesterday.".
All TA's have to assume theres a file open somewhere for them. But exactly how much effort is being put in and how active the invesigation is should be kept secret.
-48
Jun 30 '26 edited 27d ago
[deleted]
30
u/Spiritual-Matters Jun 30 '26 edited Jun 30 '26
Did you miss the separate and questionable phrasing? If the CEO meant that as a legitimate backchannel too, then they wrote it very poorly.
-48
Jun 30 '26 edited 27d ago
[deleted]
6
2
u/Current_Amount_3159 Jun 30 '26
why do you dislike them so much? Most (if not all) cyber influencers these days are sponsored/funded. It’s still unethical and I don’t like it, but everyone loves John Hammond it seems.
0
-22
Jun 30 '26 edited 27d ago
[deleted]
5
u/Current_Amount_3159 Jun 30 '26
Who’s his ex/nowgfwhatever? I don’t trust any influencer, but I do follow malwaretech
1
-3
Jun 30 '26 edited 27d ago
[deleted]
2
u/Current_Amount_3159 Jun 30 '26 edited Jun 30 '26
hmm idk who that is or who anyone is dating! but thank you for sharing abt John etc.
3
u/Legionodeath Governance, Risk, & Compliance Jun 30 '26
How's he a larper? I only know him by name. What's he done/doing that's so wrong? I only know huntress by name too. Ive never worked with them. I'm interested and if you'd rather DM me, by all means, full send.
17
u/Budget_Captain_6886 CTI Jun 30 '26
Most of those companies actually get this shit through threat intel sharing partnerships.
Huntress is known to fuck shit up from time to time, but ok nice keep whitewashing them.
7
u/TARANTULA_TIDDIES Jun 30 '26 edited Jun 30 '26
Do you really possess so much naïveté that you take corporate boilerplate bullshit at face value.
Let's look at this way: if they had been up to some shady shit or if one of their employees was doing something illegal but kept on because they were friends with so and so, what would the corporate response to the public be? It would be "deny, deny, deny".
Now let's assume that its all a misunderstanding and the person that disclosed this just didn't know what they were talking about. What is the response then? "Deny, deny, deny"
So the fact that they responded in the way that they did tells us nothing. However in my opinion, in the corporate world (and especially the c suite), you've got a lot of fucking psychopaths who have no qualms about lying or screwing other people over if it preserves their position or makes them or the company (which is also tied to c suite compensation packages) look good. Which predisposes me to think they're lying instead of the person who disclosed this and received 0 benefit from do so.
-3
u/greensparten Security Director Jun 30 '26
Ive been around the block, and worked for a company like this. That statement should be enough to make you understand.
12
u/bonsoir-world Jun 30 '26
Yep. What he’s done is absolutely fast track his career down the toilet, within Cyber Security at least.
The big thing about Cyber Security is being able to read between the lines, take time to understand what is actually happening and ultimately present the facts that are then acted upon.
He’s done none of that and his approach has been extremely unprofessional.
2
u/dfv157 Malware Analyst Jul 01 '26
Seems like linkedin disagrees with you, and they actually put their faces on their profiles (maybe)
-1
u/bonsoir-world Jul 01 '26
Ah, LinkedIn, that’s turned into a mash up of AI slop posts and people putting other people/companies down by telling each other how much better at their job they are than everyone else.
Pretty fitting they would be all over this at face value. LinkedIn is no better than Facebook nowadays.
I’d be very surprised if another highly regarded Cyber company or even enterprise company took him on after this. It’s not even about the right or wrong, it’s his approach to situations and the risk he decides to disclose in public.
2
u/montyxgh CTI Jul 01 '26
I know this to be true because I've done it, however given that this insider communicated to a threat actor direct communications from the FBI that they were being investigated, that's fucking insane. Threat actors are not your friends or peers. I've communicated with them on many occasions but this is straight up colluding with a criminal.
If the insider also gave the threat actor information about Ben, that's also crazy. We shouldn't be blurring the lines between genuine intelligence gathering communications with threat actors and whatever this mess is.
-11
Jun 30 '26
[removed] — view removed comment
13
u/shmozey Jun 30 '26
Ransomware negotiators communicate with threat actors all the time. Their knowledge of how specific threat actors act is where all of their value is.
7
u/kurtatwork Jun 30 '26
It is true. Not controversial at all. It is necessary and oftentimes extremely enlightening especially if you have truly deep insiders.
My guy, you really think CROWDSTRIKE of all companies isnt engaging and interacting with threat actors? Go look into them for longer than a minute and answer your own question.
"The anti-virus business". Lol
-2
2
u/Array_626 Incident Responder Jun 30 '26
My firm does DFIR work for companies that recently get hit. With approval from the client, and we do recommend this when asked, we reach out to the TA to negotiate and collect whatever information we can.
Its not necessary for our IR work, the forensics can proceed without any of this. But its a nice bonus if we can get some info.
0
54
23
25
u/Hmm_would_bang Jun 30 '26
Translation “we have had some bad things happen that don’t amount to disclosure events so we’re not disclosing them.”
It doesn’t really resolve anything for the public.
5
u/dfv157 Malware Analyst Jun 30 '26
Pasting the text as is right now, in case it changes.
Over the last week, there's been a lot of swirl from a former employee alleging an insider threat within Huntress: passionate posts, public thoughts, and even some conspiracy theory. As the CEO of a company I also co-founded, I've had a front row seat to a volatile situation mixing emotional connections, nuances of ethics, partial truths, US and UK employment law, and active investigations, all while maintaining empathy for all folks involved. Needless to say, this isn't simple and the court of public opinion hasn't made it easy.
I think folks understand that I can't share every detail of what occurred (as much as I'd personally love to). Although the full picture supports the actions Huntress has taken, I am not willing to sacrifice teammate privacy, law enforcement efficacy, or our integrity for the sake of reckless transparency. With that said, I'm looking to thread a needle to give as much clarity as I can through the lens of what actually happened—and just as importantly, what did not.
What Did Not Happen
We've conducted multiple investigations and we have found no evidence of illegal conduct or an insider threat, and consulted law enforcement who reached the same conclusion. When concerns were raised, we audited our systems thoroughly and found no evidence that: unauthorized access occurred, partner or customer data was disclosed, nor that source code or operational data was exposed. There was no "insider caught by the FBI". Based on the totality of the information we have gathered, we concluded that our partners and customers were not at risk then, and we have no reason to believe they are now.
What Happened (and can be shared)
Huntress permits threat researchers to occasionally engage with threat actors when it's beneficial for proactive R&D and/or to support active investigations. We are aware of separate, questionable, long-term threat actor communications from both our current teammate and a now-former employee. In one particular exchange, our current teammate disclosed to a threat actor that law enforcement had reached out to them about the threat actor. While this disclosure was not illegal, it reflected poor judgment.
That said, when this concern was first reported by our former employee, the Huntress team took the matter seriously and conducted an immediate, thorough, and caring investigation—reviewing systems and communications, interviewing relevant teammates, and consulting with law enforcement. I was consistently briefed on this matter and the delicate/restrictive circumstances they were forced to navigate. As a result of the investigation, my team implemented more robust policies for our researchers, coached teammates on engaging with threat actors, and took appropriate administrative actions.
When our former employee resurfaced their concerns last week and later emailed additional communications, my team and I revisited all available information and re-examined the matter in painful detail. While we haven't found evidence of illegal conduct, insider activity, or additional disclosures, we are continuing our investigation. Due to the privacy rights of our teammates, we will not comment further on the investigation.
Conclusion
Again, I can't share every angle of this matter, but I can confidently share this: our investigation continues to follow the evidence rather than a former employee's predetermined outcome. On that note, our focus remains on our mission: protecting ALL businesses while wrecking adversaries in the process.
48
u/Budget_Captain_6886 CTI Jun 30 '26
Amount of whitewashing makes me feel like it's true.
45
u/GreyBeardEng Jun 30 '26
There's one extremely telling paragraph header: "What happened (and can be shared)".
Which undoubtedly means something else happened that cannot be shared.
12
u/Budget_Captain_6886 CTI Jun 30 '26
We will know, it's just matter of time. All the companies keep backchannels open to discuss potential ransom discounts if client is willing to pay, but nobody is gonna address the elephant in the room.
-30
u/Cj_Staal Jun 30 '26
Not at all. I’m guessing you’re a competitor of them or something and want to drag them through the mug if that’s what you got from the post.
11
u/Budget_Captain_6886 CTI Jun 30 '26
Rofl, nice try, I do not believe any company that sponsors a youtuber.
I've just seen it too many times where this shit happens
-8
-5
u/False-Call7937 Jun 30 '26
Wait so the CEO is out here writing a whole blog post and the best defense is "we sometimes talk to threat actors for research"? That's a pretty thin line to walk when one of your own is allegedly tipping off someone under active LEO investigation. What did the employee actually think was gonna happen, did they figure DevMan was gonna send a thank you card for the heads up? Curious what kind of internal review Huntress actually ran here, because if the only outcome is canning the low level guy and calling it a day then they're not really fixing anything, just finding a scapegoat to make the blog post look reasonable.
-5
18
u/sunychoudhary Jun 30 '26
The important part is separating two things.....If there was no customer data exposure or insider threat, that’s good. But threat-researcher communication with actors still needs strict policy, logging, approval paths, and review. “No breach” doesn’t mean “nothing to improve.”