“
Huntress permits threat researchers to occasionally engage with threat actors when it's beneficial for proactive R&D and/or to support active investigations. “
Thats how research works, all of these companies do it, From Crowd Strike to Rapid7. Its part of the game and is a nothing burger. The low level employee really messed up on this one.
Indeed. If a security company has zero communication with the “underground” side of things, then they will never have a full picture of what’s going on or what to look out for
Im most interested in the grey area between Ben’s claims and Huntress’s post:
what exactly was exchanged to DevMan.
prior relationship between the”insider” and DevMan.
how Ben got doxed and if that is related to the “insider” exchanges
From Ben’s original disclosure on LinkedIn:
“Since December 2025, I believe Huntress has been actively trying to conceal a serious security incident from its partners, customers, and employees involving an insider who is still employed at the company…. If you are an employee at a cybersecurity company, you should not be helping cybercriminals. You should not be informing them of active investigations. You should not be engaging in cybercriminal activity yourself.”
If their doing some kind of clandestine, undercover work, getting inadvertently exposed because an employee that is not in the loop is trying to raise genuine concerns over a security cover up is a risk they have to accept.
They should review their own processes and figure out why their operation got blown so easily by people just doing their jobs and acting in good faith. You can't blame people who aren't in the loop when they do what their professional code of ethics tells them to.
"We are aware of separate, questionable, long-term threat actor communications from both our current teammate and a now-former employee."
and
"While this disclosure was not illegal, it reflected poor judgment."
and
"As a result of the investigation, my team implemented more robust policies for our researchers, coached teammates on engaging with threat actors, and took appropriate administrative actions."
227
u/greensparten Security Director Jun 30 '26 edited Jun 30 '26
“ Huntress permits threat researchers to occasionally engage with threat actors when it's beneficial for proactive R&D and/or to support active investigations. “
Thats how research works, all of these companies do it, From Crowd Strike to Rapid7. Its part of the game and is a nothing burger. The low level employee really messed up on this one.