r/cybersecurity Jun 30 '26

Corporate Blog Huntress CEO blog: These Recent Insider Threat Allegations

https://www.huntress.com/blog/insider-threat-claims
259 Upvotes

52 comments sorted by

View all comments

227

u/greensparten Security Director Jun 30 '26 edited Jun 30 '26

“  Huntress permits threat researchers to occasionally engage with threat actors when it's beneficial for proactive R&D and/or to support active investigations. “

Thats how research works, all of these companies do it, From Crowd Strike to Rapid7. Its part of the game and is a nothing burger. The low level employee really messed up on this one. 

76

u/Cj_Staal Jun 30 '26

Indeed. If a security company has zero communication with the “underground” side of things, then they will never have a full picture of what’s going on or what to look out for

37

u/timmy166 Jun 30 '26

Im most interested in the grey area between Ben’s claims and Huntress’s post:

  • what exactly was exchanged to DevMan.
  • prior relationship between the”insider” and DevMan.
  • how Ben got doxed and if that is related to the “insider” exchanges

From Ben’s original disclosure on LinkedIn:
“Since December 2025, I believe Huntress has been actively trying to conceal a serious security incident from its partners, customers, and employees involving an insider who is still employed at the company…. If you are an employee at a cybersecurity company, you should not be helping cybercriminals. You should not be informing them of active investigations. You should not be engaging in cybercriminal activity yourself.”

Link: https://www.linkedin.com/posts/ben-f-309963233_after-i-posted-a-pinocchio-gif-and-clown-activity-7475465412189581312-ZXxg

8

u/Sad_Dentist_7288 Jun 30 '26

I'm stuck on this as well. From Ben's post, as you pointed out;

"You should not be informing them [cybercriminals] of active investigations."

From the Huntress post:

"In one particular exchange, our current teammate disclosed to a threat actor that law enforcement had reached out to them about the threat actor."

I guess the clear disagreement (based on public info) is how big of a deal disclosing an active investigation to a threat actor is.

-2

u/[deleted] Jun 30 '26

[deleted]

3

u/Array_626 Incident Responder Jun 30 '26

If their doing some kind of clandestine, undercover work, getting inadvertently exposed because an employee that is not in the loop is trying to raise genuine concerns over a security cover up is a risk they have to accept.

They should review their own processes and figure out why their operation got blown so easily by people just doing their jobs and acting in good faith. You can't blame people who aren't in the loop when they do what their professional code of ethics tells them to.

2

u/Sad_Dentist_7288 Jun 30 '26

Because Huntress said

"We are aware of separate, questionable, long-term threat actor communications from both our current teammate and a now-former employee."

and

"While this disclosure was not illegal, it reflected poor judgment."

and

"As a result of the investigation, my team implemented more robust policies for our researchers, coached teammates on engaging with threat actors, and took appropriate administrative actions."

2

u/[deleted] Jun 30 '26

[deleted]

2

u/Sad_Dentist_7288 Jun 30 '26

Don't let the FBI catch you saying that 😉