Cybernews Huntress Employee Allegedly Informs Ransomware Operator of FBI Investigation
Article Content
- •A Huntress employee allegedly informed ransomware operator Devman about an FBI probe.
- •The CEO stated the disclosure was poor judgment but not illegal, allowing engagement with threat actors for research.
- •Former analyst Ben Folland claims this constitutes an insider threat and could endanger clients.
Huntress CEO Kyle Hanslovan addressed allegations that a current employee tipped off ransomware operator Devman about an FBI investigation. Former analyst Ben Folland claimed that the employee disclosed sensitive communications from law enforcement, which he argues constitutes an insider threat. Hanslovan acknowledged the poor judgment but stated that the disclosure was not illegal and emphasized that Huntress allows engagement with threat actors for research purposes. The incident has raised concerns about the company's internal practices and the potential risk to clients. Folland, who left Huntress in February, asserted that the employee's actions could lead to reputational damage and put clients at risk. The FBI has been notified of the situation, but no further details have been released. Huntress is continuing its investigation and has implemented new policies for its researchers.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Conti and Huntress in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Permanent Data Loss from Iranian Drone Strikes on AWS in Middle East Amazon Web Services (AWS) reported that multiple Iranian drone strikes have caused permanent data loss in its cloud infrastructure located in Bahrain and the UAE. The strikes, which began in March 2026, targeted AWS data centers in retaliation for US and Israeli military actions against Iran. AWS confirmed that it…