Insider Allegations

Threat Analyst Accused of Warning Hacker About FBI Investigation

Hacker, FBI investigation, insider threat, Huntress, Huntress employee accused of warning ransomware operator about FBI probe, huntress fbi, FBI, Investigation
Facebook
X
LinkedIn
Reddit
WhatsApp

A former analyst at cybersecurity company Huntress has accused a current employee of leaking sensitive information about an ongoing investigation by the FBI to a ransomware operator.

At the center of the allegations are alleged communications between a Huntress threat researcher and the operator of the “Devman” ransomware group, which is believed to be based in Russia. The group reportedly uses a modified version of the DragonForce malware, itself derived from leaked Conti source code.

Ad

Huntress is a US-based cybersecurity provider specializing in managed detection and response (MDR) services for small and mid-sized businesses as well as IT service providers. The platform combines 24/7 endpoint and network monitoring with human threat analysts.

The accusations were made public by Ben Folland, a former Huntress employee who left the company in February and previously worked in security operations. Folland claims that the Devman group has since been actively targeting him and his family.

What the employee is accused of

According to Folland, the FBI had contacted the Huntress employee seeking information about the Devman ransomware operation. Instead of cooperating, he alleges, the employee refused to engage with investigators and forwarded the FBI’s full communication — including screenshots containing the names of agents involved — directly to the ransomware operator.

Ad

Folland argues that this effectively warned the cybercriminal that he was under investigation. He describes the behavior as a clear insider threat and compares it to a bank employee alerting a fraud suspect to an active police investigation. In his view, professionals working in cybersecurity firms must not assist cybercriminals or disclose ongoing law enforcement activity.

Ben F. Screenshot (Source: LinkedIn)
Source: LinkedIn Screenshot

Huntress CEO responds

Huntress CEO Kyle Hanslovan acknowledged in a recent blog post that the company was aware of “questionable, long-term interactions” between the employee and the threat actor.

He confirmed the core allegation that the employee informed the cybercriminal that law enforcement agencies had reached out regarding the case. While this was not unlawful, Hanslovan described it as a serious lapse in judgment.

“Huntress permits threat researchers to engage with threat actors in limited cases when it supports proactive research and development or assists ongoing investigations. We are aware of separate questionable long-term communications with threat actors involving both a current team member and a former employee. In one instance, a current team member disclosed to a threat actor that law enforcement had contacted us regarding that actor. While not illegal, it reflected poor judgment.”

Huntress-CEO Kyle Hanslovan

Hanslovan rejected the classification of the case as an insider threat. When the allegations first surfaced, he strongly denied wrongdoing, although without providing details at the time.

He added that the internal investigation has since resulted in stricter policies governing researcher interactions with threat actors, along with additional training measures. The company also implemented “appropriate personnel actions.” However, Huntress stated it has found no evidence of illegal activity, deliberate insider misconduct, or broader data leakage so far.

Due to ongoing internal proceedings and employee privacy considerations, the company said it would not provide further comment.

(lb)

Ad

Weitere Artikel